Cybersecurity firm JUMPSEC has documented a phishing kit run by the North Korea-linked group BlueNoroff that lures crypto professionals into fake Zoom and Microsoft Teams calls, then scans their browsers for wallet extensions. A separate Daily NK report says a criminal organization allegedly hacked North Korea’s own central bank and moved the proceeds into cryptocurrency.
North Korean hackers now open the attack with a video call. JUMPSEC uncovered a phishing operation run by BlueNoroff, a North Korea-linked hacking group whose scheme lures crypto professionals into fake Zoom and Microsoft Teams meetings.
The attackers hijack Telegram accounts belonging to people victims already trust, then send meeting invites through those accounts. Once inside the fake call, victims are asked to turn on their webcam. JUMPSEC says the group accidentally exposed its own JavaScript source code, a mistake that gave researchers a rare look at how the scheme works.
The fake call screens victims before any malware runs
Each invite leads to a lookalike domain built to mimic Zoom or Teams, and victims who join may see pre-recorded participants on screen while an operator watches their live camera feed. JUMPSEC found the Teams version of the kit looks more convincing than the Zoom one, adding fake device settings, emoji reactions, and virtual backgrounds.
Before any malware gets involved, the platform quietly scans the browser for wallet extensions tied to Ethereum, Solana, and other blockchain networks. That step lets BlueNoroff filter out low-value targets and focus only on people worth attacking further, according to JUMPSEC’s findings.
Windows and macOS victims get separate infection paths
Once the scan finishes, victims are prompted to install a fake “SDK update” that triggers what researchers call a ClickFix attack. On Windows machines, the update launches PowerShell scripts that pull down more malware and search for Telegram data and browser wallet extensions, while Mac users download what looks like a normal installer as a second-stage stealer loads quietly in the background.
The malware can capture browser credentials, Chrome master keys, and full Telegram sessions, along with cryptocurrency wallet data and system information. Because Telegram sessions are stolen too, attackers can potentially reuse a hijacked account to target the victim’s own contacts next.
Researchers found multiple versions of the platform sitting on the same infrastructure, plus an unfinished Google Meet variant that suggests BlueNoroff plans to expand beyond Zoom and Teams. JUMPSEC said the continued upgrades to the Teams interface suggest ongoing refinement: “This looks like a sustained campaign, not a one-off effort”.
North Korean IT workers allegedly hacked their own central bank
North Korea’s own financial system has become a target too. A criminal organization allegedly hacked internal networks at the Central Bank of Korea and the Foreign Trade Bank, according to a separate Daily NK report, converting stolen state funds into cryptocurrency before smuggling it across border regions.
A source told Daily NK the ringleaders were former soldiers from a cyber operations unit under the General Reconnaissance and Intelligence Bureau, who after leaving the military allegedly recruited students from Kim Chaek University of Technology and Pyongyang University of Science. Stolen funds were reportedly split into small units, moved to overseas crypto wallets, then converted back into cash through Chinese brokers and exchanged for US dollars and yuan near Sinuiju and Hyesan.
Investigators traced the scheme after spotting irregular transaction records and unusual overseas IP access. The National Intelligence Agency reportedly traced heavy crypto traffic to a house in Pyongyang, raided on the night of the 12th, where ringleaders and IT personnel were arrested and computer equipment and burner phones seized.
Sources:
Trading involves risk.