BlueNoroff scans crypto wallets during a fake Zoom call and selectively “poisons” them with malicious intent

ZM4.62%
MSFT0.06%
ETH4.62%
SOL2.62%
AAPL3.57%
Key Takeaways
  • BlueNoroff scans cryptocurrency wallets during fake Zoom calls using EIP-6963 standard and selectively deploys malware.
  • BlueNoroff targets cryptocurrency professionals with 80% working in crypto or blockchain finance across 20+ countries.
  • BlueNoroff uses Windows PowerShell to disable Microsoft Defender and macOS malware to steal Chrome keys from Keychain.

This week, the UK security company JUMPSEC released a source code analysis report revealing the latest attack pattern used by the North Korean hacker group BlueNoroff: during fake Zoom and Microsoft Teams calls, it uses the EIP-6963 standard and traditional browser techniques to scan the target users’ crypto wallets, selects high-value targets based on the wallet value, and then selectively delivers malware.

BlueNoroff Fake Video Call Attack Flow

According to JUMPSEC’s source code analysis, BlueNoroff’s full attack flow is as follows:

· The attacker takes over the Telegram account of a target contact in the cryptocurrency space, sending a fake Calendly meeting invitation with a link to a misspelling-squatted fake meeting domain

· After the victim visits the fake meeting page, the toolkit immediately scans the browser using the EIP-6963 standard (looking for Ethereum connections), while also detecting non-EVM wallets (such as Solana tools). The scan results are pushed to an operator-controlled dashboard, and the victim remains unaware throughout

· After the call begins, the page shows “Waiting for other participants.” The operator plays a pre-recorded video; the AI generates avatar composites by stitching to the body actions captured earlier, and tells the victim, “Your microphone isn’t working”

· Based on the wallet data shown on the dashboard, the operator decides whether to deliver malware. It pops up a fake “Zoom SDK Update” prompt to trick the victim into running it

· Each hijacked account is directed to other cryptocurrency-space contacts of that individual, forming a chain of attack targets

Differential Malware for Windows and macOS

According to JUMPSEC’s technical analysis, BlueNoroff uses different malware for different systems as follows:

Windows:A copied ClickFix command launches a small PowerShell loader process, downloads a VBScript script, then adds Microsoft Defender to an exclusion list and restarts it to make the change permanent. The payload collects system information, scans browser wallet extensions (including the ID lists for Chrome, Edge, Brave, Opera, Vivaldi, and Firefox), matches known wallet extensions such as MetaMask, and searches for Telegram Web files.

macOS:It injects forged Zoom or Teams installation processes. A theft program running silently in the background steals system data and Chrome’s master keys from Apple’s “Keychain,” and exfiltrates via Telegram.

JUMPSEC found four macOS versions between April 22 and July 15; Arctic Wolf and JUMPSEC found five phishing toolkit versions between May 31 and July 14. These toolkits can fully compromise systems in under five minutes.

FAQ

How does BlueNoroff scan crypto wallets during the fake calls?

According to JUMPSEC’s source code analysis, the BlueNoroff toolkit scans the target’s Ethereum connection using the EIP-6963 standard and traditional browser techniques, while also detecting non-EVM wallets such as Solana. The scan results are pushed in real time to the operator’s dashboard, and the victim is unaware throughout.

Who are the main targets of BlueNoroff attacks?

According to Arctic Wolf’s statistics, 80% of the attack targets are in the cryptocurrency or blockchain finance industry, 45% are founders or CEOs, and 41% of victims are located in the United States. As of the report’s release, more than 100 victims have been identified across more than 20 countries.

How are macOS users infected with BlueNoroff?

According to JUMPSEC’s analysis, macOS users are infected by clicking forged Zoom or Teams installation programs. The background stealing program steals system data and Chrome’s master keys from Apple’s Keychain and sends them to the attackers via Telegram.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments