discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

North Korea-linked BlueNoroff is running a phishing kit that impersonates Zoom and Microsoft Teams to fingerprint crypto wallets before delivering malware, using hijacked Telegram accounts as the entry point.

By Ravie Lakshmanan·Jul 24·thehackernews.com·4 min read

Intelligence analysis by Llama

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Image: thehackernews.com

JUMPSEC details a BlueNoroff operation that hijacks trusted Telegram contacts, lures victims to fake Zoom/Teams meetings via Calendly, and fingerprints browser-based crypto wallets before triggering a ClickFix malware payload — blending AI-generated deepfake video with self-propagating account compromise.

Why it matters

The campaign represents a maturation in North Korea's crypto-targeting tradecraft, combining supply-chain-style trust abuse, AI-generated meeting video, and pre-malware wallet reconnaissance to selectively hit high-value victims rather than spray-and-pray.

Imagine a thief who pretends to be a friend your mom trusts, invites you to a video call, and only steals your piggy bank if you actually have one in your room. That's what these North Korean hackers are doing with fake Zoom meetings and AI-made faces, and they keep using the friends they trick to trick even more people.

Analysis

A Pipeline, Not a Phish

JUMPSEC frames the BlueNoroff activity not as isolated phishing runs but as an "operator-driven victim acquisition platform." The key differentiator is sequencing: the kit fingerprints a victim's installed cryptocurrency wallet extensions (MetaMask and similar) on the browser before the malware payload is even triggered. That recon step lets the operator decide whether a target is worth burning the implant on, turning what is traditionally a volume game into a qualified-lead funnel. For defenders, this matters because the click that delivers the loader is no longer the decisive moment; the wallet enumeration that precedes it is the real signal that a high-value target is in scope.

The pipeline starts with compromised Telegram accounts belonging to people the target has met in real life. According to JUMPSEC, lure Calendly links are sent from those hijacked sessions, making the initial outreach look like a legitimate scheduling ping rather than a cold message. Every successful compromise then becomes fuel for the next one, because the stealer harvests Telegram Web session cookies and uses them against the victim's own contact list. JUMPSEC describes this as a self-sustaining chain, and Sekoia has tracked a parallel North Korea-aligned cluster under the name ClickFake Interview that uses the same ClickFix-style pretexts.

The Fake Meeting Has a Face

The most editorially novel element is what happens after the victim lands on the typosquatted Zoom or Teams page. They are prompted for a name and camera permission, and the webcam stream is silently relayed to the operator's panel via mediasoup WebRTC. The victim is then shown a Zoom-style waiting room, and a pre-edited video of a plausibly familiar person "joins" the call. JUMPSEC notes that the faces in that video are AI-generated headshots produced with OpenAI's ChatGPT, composited onto authentic body movements captured during prior attacks. Each successful compromise, in other words, supplies the body-language source material for the next deepfake meeting.

The operator still controls the meeting from the panel, sending fake "your microphone isn't working" prompts and eventually surfacing a "Zoom SDK Update" that triggers the ClickFix payload. The Teams variant is reportedly more polished than the Zoom version, with emoji reactions, mobile/tablet blocking, and more advanced wallet probes. That asymmetry suggests the actors are iterating quickly and treating each lure domain as a versioned experiment rather than a one-off site.

Two Kill Chains, One Stealer

On Windows, the ClickFix command runs a PowerShell loader that fetches a VBScript implant, disables Microsoft Defender, adds C:\Users to the exclusion path, and force-restarts Defender so the exclusions stick. The implant then inventories Telegram Web artifacts across Chrome, Edge, Brave, and Firefox, enumerates installed extensions across Chromium-family browsers plus Opera, Opera GX, Vivaldi, and Firefox, and matches the extension IDs against known wallet signatures. The macOS chain drops a shell-scripted fake installer that extracts Chrome master keys from iCloud Keychain and exfiltrates system metadata plus credentials to a Telegram channel named "Aurora," with the bot token and chat ID hard-coded into the stealer binary.

Querying that Telegram bot API linked the exfiltration channel to an operator handle, @alchemy_john_mac, who as recently as May 2026 was seen in the MAIV cryptocurrency group asking admins about vesting contracts. That blend of on-chain and off-chain targeting — wallet reconnaissance on the victim's machine and social engineering inside the victim's professional groups — is what makes the campaign difficult to disrupt with any single control.

Key points

  • BlueNoroff is running an 'operator-driven victim acquisition platform' that fingerprints installed crypto wallet extensions before triggering ClickFix malware, per JUMPSEC.
  • Initial access is hijacked Telegram accounts belonging to people the target has met in person, with Calendly links leading to typosquatted Zoom and Microsoft Teams domains.
  • The fake meeting uses AI-generated ChatGPT headshots composited over authentic body movements captured in prior attacks, relayed via mediasoup WebRTC.
  • The macOS stealer exfiltrates Chrome master keys from iCloud Keychain to a Telegram channel called Aurora, tied to the handle @alchemy_john_mac.
  • The Windows implant enumerates extensions across Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox to match wallet signatures like MetaMask.
The Upside

The wallet-fingerprinting stage is a behavioral signal that defenders can hunt for at the browser level, and the typosquatted Zoom/Teams infrastructure is enumerable and sinkholeable. Public attribution to a named Telegram handle (@alchemy_john_mac) and a known exfiltration channel (Aurora) gives the crypto community concrete IoCs to monitor and ban.

The Downside

The self-propagating Telegram account takeover means each successful compromise expands the lure pool for the next, and the AI-generated face composites make the social engineering increasingly resistant to user-side skepticism. Because the kit selectively delivers full payloads only after confirming a high-value wallet, low-fidelity endpoint alerts are likely to miss the most damaging cases.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycryptoai-agentsmalware

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Jul 24, 2026

Source

thehackernews.com

Share

Topics

securitycryptoai-agentsmalware

Related

More from this desk

Jul 24·bleepingcomputer.com

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. This campaign has been ongoing since at least June and impacts organizations in various sectors.

Jul 24·bleepingcomputer.com

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft blames a maintenance bug for a massive Microsoft 365 outage that affected various services, including Teams, SharePoint, and OneDrive. The company says a bug in its automated network maintenance request system caused the outage by mistakenly removing IP routes f…

Jul 24·thehackernews.com

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers H0j3n and Aniq Fakhrul published a working exploit that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. The flaw, codenamed Certighost, was patched by Microsoft ten days earlier as CVE-…

Jul 24·bleepingcomputer.com

Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A has confirmed a data breach affecting over 13,000 customers due to credential stuffing attacks. The attackers accessed customers' names, email addresses, Chick-fil-A One membership numbers, and credit/debit card information.