Teacher using a laptop for an online meeting, illustrating BlueNoroff’s fake meeting campaign

BlueNoroff’s Fake Video Meetings Profile Crypto Wallets Before Malware Delivery

July 26, 2026 10:27 am Comments

Crypto professionals are being lured into counterfeit video meetings built to look familiar at precisely the moment a trusted contact appears to need them. The BlueNoroff campaign turns that ordinary invitation into a staged technical failure, a malicious command, and an operating-system-specific malware path.

The approach combines hijacked Telegram accounts, fake meeting domains, and convincing imitations of Zoom or Microsoft Teams. The findings describe abuse of brands and relationships through social engineering; they do not indicate that Telegram, Zoom, Microsoft, or their genuine software was breached.

Researchers reached unusually deep into the operation because the people running it exposed JavaScript source maps on active infrastructure. That mistake gave investigators source code from a working phishing kit, extending visibility beyond the page a target would see.

JUMPSEC obtained and analyzed the exposed code and attributed the active phishing kit to North Korea-linked BlueNoroff. Its report describes a coordinated platform that impersonates video-meeting services, identifies a visitor’s environment, checks for crypto-wallet browser extensions, and steers that visitor toward malware prepared for Windows or macOS.

The recovered build included Zoom and Microsoft Teams impersonation paths, while its code referenced a likely Google Meet variant that had not been implemented. That distinction matters because the report documents counterfeit interfaces on fake domains, not malicious delivery through the companies’ real meeting products.

The investigation also connected the technical infrastructure to outreach through hijacked Telegram accounts belonging to trusted industry contacts. In three analyzed cases, the invitation arrived through a relationship the recipient could recognize, and two accounts that had been compromised were then used to contact more people.

Once a target entered the fake meeting, the site requested webcam access and played edited footage designed to sustain the illusion of a live call. AI-generated faces were composited over recorded body movements, after which a fabricated audio or software development kit problem created the opening for a ClickFix instruction.

That sequence makes the invitation itself part of the technical chain. A message from a known account directs the recipient to a fake domain, and the fake domain performs the browser-side checks that prepare the next stage.

The report’s three cases do not establish that every recipient was infected or lost cryptocurrency. They show how one compromised communications identity can become an instrument for approaching additional contacts with a meeting request that appears to come from inside the industry.

On the meeting page, the webcam request supplies another layer of plausibility. The pre-edited video can make the visitor feel that other participants are already present, while the synthetic faces and existing body motion preserve the appearance of human activity.

The manufactured audio or SDK fault then reframes the encounter as routine troubleshooting. Instead of ending the meeting, the page presents a fix that asks the target to copy and execute what appears to be corrective text.

The ClickFix mechanism changes what has been copied, substituting a malicious command for the expected text. The danger sits in the gap between what the page appears to provide and what the operating system is actually asked to run.

Before malware delivery, the platform also fingerprints browser wallets across both EVM and non-EVM ecosystems. The recovered behavior establishes that wallet presence was part of the profiling process, although it does not prove that every profiled browser held funds or that every encounter produced a theft.

That wallet check places crypto-specific reconnaissance inside a broader social-engineering flow. It allows the phishing platform to collect information about the browser environment before the Windows or macOS delivery route proceeds.

JUMPSEC reconstructed a distinct Windows chain from the recovered source. That path downloaded a VBScript implant and attempted to add a Microsoft Defender exclusion after the counterfeit meeting page had pushed the target toward the malicious command.

The attempted Defender exclusion belongs to the recovered attack code, not to Microsoft Teams or Windows behaving as designed for a real meeting. The brand imitation supplies credibility, while the downloaded code and subsequent system change come from the attackers’ infrastructure.

The macOS variants used fake Zoom or Teams installers as the visible lure while payloads executed in the background. Again, the installers were counterfeits delivered through fake domains, and the report does not say that authentic Zoom or Teams packages carried the malware.

Separating the two operating-system paths is important because the same front-end deception can lead to different execution methods. A target may see a similar meeting failure, yet the code can tailor what follows to the device being used.

JUMPSEC said infrastructure assessed with high and medium confidence remained active as of July 22, 2026. That date limits the status claim: it establishes observed activity at the stated cutoff, not a guarantee about every domain or server afterward.

The exposed source maps also reveal the boundaries of what investigators recovered. Although a likely Google Meet variant appeared in the code, it was not implemented in that build, so the demonstrated impersonation paths remain Zoom and Microsoft Teams.

The campaign’s strongest lever is accumulated trust: a familiar Telegram identity, a recognizable meeting brand, an apparently populated call, and a fix for a plausible technical problem. Each element supports the next without requiring any breach of the legitimate messaging or meeting platforms.

For crypto professionals, the report narrows the warning signs to a precise sequence instead of a vague phishing label. An unexpected meeting link can open a counterfeit page, request camera access, simulate participants, claim a technical failure, alter clipboard content, inspect wallet extensions, and deliver code matched to the operating system.

The evidence supports a focused conclusion about an active, engineered intrusion path while leaving losses and outcomes case-specific. BlueNoroff’s recovered kit joined relationship hijacking, fake domains, browser profiling, and separate malware routes into one meeting experience designed to make malicious execution feel like ordinary troubleshooting.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.