BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
North Korea-linked BlueNoroff is running a phishing kit that impersonates Zoom and Microsoft Teams to fingerprint crypto wallets before delivering malware, using hijacked Telegram accounts as the entry point.
Intelligence analysis by Llama

JUMPSEC details a BlueNoroff operation that hijacks trusted Telegram contacts, lures victims to fake Zoom/Teams meetings via Calendly, and fingerprints browser-based crypto wallets before triggering a ClickFix malware payload — blending AI-generated deepfake video with self-propagating account compromise.
Imagine a thief who pretends to be a friend your mom trusts, invites you to a video call, and only steals your piggy bank if you actually have one in your room. That's what these North Korean hackers are doing with fake Zoom meetings and AI-made faces, and they keep using the friends they trick to trick even more people.
Analysis
A Pipeline, Not a Phish
JUMPSEC frames the BlueNoroff activity not as isolated phishing runs but as an "operator-driven victim acquisition platform." The key differentiator is sequencing: the kit fingerprints a victim's installed cryptocurrency wallet extensions (MetaMask and similar) on the browser before the malware payload is even triggered. That recon step lets the operator decide whether a target is worth burning the implant on, turning what is traditionally a volume game into a qualified-lead funnel. For defenders, this matters because the click that delivers the loader is no longer the decisive moment; the wallet enumeration that precedes it is the real signal that a high-value target is in scope.
The pipeline starts with compromised Telegram accounts belonging to people the target has met in real life. According to JUMPSEC, lure Calendly links are sent from those hijacked sessions, making the initial outreach look like a legitimate scheduling ping rather than a cold message. Every successful compromise then becomes fuel for the next one, because the stealer harvests Telegram Web session cookies and uses them against the victim's own contact list. JUMPSEC describes this as a self-sustaining chain, and Sekoia has tracked a parallel North Korea-aligned cluster under the name ClickFake Interview that uses the same ClickFix-style pretexts.
The Fake Meeting Has a Face
The most editorially novel element is what happens after the victim lands on the typosquatted Zoom or Teams page. They are prompted for a name and camera permission, and the webcam stream is silently relayed to the operator's panel via mediasoup WebRTC. The victim is then shown a Zoom-style waiting room, and a pre-edited video of a plausibly familiar person "joins" the call. JUMPSEC notes that the faces in that video are AI-generated headshots produced with OpenAI's ChatGPT, composited onto authentic body movements captured during prior attacks. Each successful compromise, in other words, supplies the body-language source material for the next deepfake meeting.
The operator still controls the meeting from the panel, sending fake "your microphone isn't working" prompts and eventually surfacing a "Zoom SDK Update" that triggers the ClickFix payload. The Teams variant is reportedly more polished than the Zoom version, with emoji reactions, mobile/tablet blocking, and more advanced wallet probes. That asymmetry suggests the actors are iterating quickly and treating each lure domain as a versioned experiment rather than a one-off site.
Two Kill Chains, One Stealer
On Windows, the ClickFix command runs a PowerShell loader that fetches a VBScript implant, disables Microsoft Defender, adds C:\Users to the exclusion path, and force-restarts Defender so the exclusions stick. The implant then inventories Telegram Web artifacts across Chrome, Edge, Brave, and Firefox, enumerates installed extensions across Chromium-family browsers plus Opera, Opera GX, Vivaldi, and Firefox, and matches the extension IDs against known wallet signatures. The macOS chain drops a shell-scripted fake installer that extracts Chrome master keys from iCloud Keychain and exfiltrates system metadata plus credentials to a Telegram channel named "Aurora," with the bot token and chat ID hard-coded into the stealer binary.
Querying that Telegram bot API linked the exfiltration channel to an operator handle, @alchemy_john_mac, who as recently as May 2026 was seen in the MAIV cryptocurrency group asking admins about vesting contracts. That blend of on-chain and off-chain targeting — wallet reconnaissance on the victim's machine and social engineering inside the victim's professional groups — is what makes the campaign difficult to disrupt with any single control.
Key points
- BlueNoroff is running an 'operator-driven victim acquisition platform' that fingerprints installed crypto wallet extensions before triggering ClickFix malware, per JUMPSEC.
- Initial access is hijacked Telegram accounts belonging to people the target has met in person, with Calendly links leading to typosquatted Zoom and Microsoft Teams domains.
- The fake meeting uses AI-generated ChatGPT headshots composited over authentic body movements captured in prior attacks, relayed via mediasoup WebRTC.
- The macOS stealer exfiltrates Chrome master keys from iCloud Keychain to a Telegram channel called Aurora, tied to the handle @alchemy_john_mac.
- The Windows implant enumerates extensions across Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox to match wallet signatures like MetaMask.
The wallet-fingerprinting stage is a behavioral signal that defenders can hunt for at the browser level, and the typosquatted Zoom/Teams infrastructure is enumerable and sinkholeable. Public attribution to a named Telegram handle (@alchemy_john_mac) and a known exfiltration channel (Aurora) gives the crypto community concrete IoCs to monitor and ban.
The self-propagating Telegram account takeover means each successful compromise expands the lure pool for the next, and the AI-generated face composites make the social engineering increasingly resistant to user-side skepticism. Because the kit selectively delivers full payloads only after confirming a high-value wallet, low-fidelity endpoint alerts are likely to miss the most damaging cases.



