Cybersecurity firm JUMPSEC reports that the North Korean-affiliated hacking group BlueNoroff is using fake Zoom and Microsoft Teams meeting pages to first identify whether victims possess cryptocurrency wallets before deciding whether to proceed with malware distribution. These attacks often originate from hijacked Telegram accounts and primarily target individuals in the crypto industry and those involved in investment.
Check the wallet first, then poison.
JUMPSEC reports that researchers have recovered the source code from a phishing tool still in use. The code reveals that attackers prepared spoofed pages for Zoom and Teams, complete with wallet scanning, control panels, and two delivery paths for Windows and macOS.
Once a victim clicks on the fake meeting page, the webpage scans the browser environment in the background to check for a connected Ethereum wallet and also identifies some non-EVM wallets, including Solana-related tools. The scan results are sent directly to the attacker's backend, and the victim usually receives no notification.
In Windows environments, the attack program also enumerates extension IDs in Chrome, Edge, Brave, Opera, Vivaldi, and Firefox variants, then compares them with common wallet extensions like MetaMask. JUMPSEC believes this means attackers assess the target's value before proceeding with further intrusions, rather than indiscriminately deploying attacks on a large scale.
Using acquaintances' accounts to increase credibility
These types of attacks typically begin with Telegram. Hackers first gain control of the victim's trusted industry contacts' accounts, then send meeting links with Calendly invitations, directing the target to a spoofed domain. JUMPSEC believes this method can create a continuous proliferation, as a stolen Telegram session can continue to help attackers reach the next batch of targets.
The fake meeting page prompts users to enter their names and turn on their cameras, transmitting the video feed back to the attacker's control panel. Once the victim joins the meeting, the page displays "Waiting for other participants to join." At this point, the attacker can play a pre-prepared video, send notifications such as "microphone malfunction," and trick the user into clicking on a so-called "Zoom SDK update."
Researchers discovered that the attendee videos on the page were not live. Attackers combined AI-generated avatars with body language captured from previous meetings to impersonate familiar contacts. Compared to the Zoom version, the Teams version is more feature-rich, including facial feedback, device settings, background effects, and more extensive wallet checks. An unfinished version of Google Meet was also found in the code.
Covers both Windows and macOS
On Windows devices, once a victim executes the command prompted by the page, a PowerShell loader may be triggered. This program downloads VBScript, adds a Microsoft Defender exclusion, and restarts Defender to make the settings take effect. Subsequently, the malware collects system information, checks browser wallet extensions, and looks for Telegram web files.
On macOS, the malware downloads fake Zoom or Teams installation packages while running a stealing program in the background. JUMPSEC found that some samples extract system information and Chrome master keys, and attempt to read data from the Apple Keychain. This data is then transmitted back via a Telegram bot, and the malware can continue downloading subsequent payloads.
JUMPSEC tracked four macOS variants spanning from April 22 to July 15, indicating that the tool is constantly being tweaked. Researchers also mentioned that Arctic Wolf had previously discovered over 80 counterfeit Zoom and Teams domains and identified 100 additional targets, approximately 80% of which originated from the crypto, blockchain finance, and related investment sectors.
Additional information:JUMPSEC recommends that encryption teams should double-check meeting links sent by acquaintances through other channels; avoid executing commands or installing temporary updates during calls; and if a Telegram session is suspected of being compromised, promptly revoke the relevant logins and isolate any devices that have executed scripts.











