BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery 6%

By Ravie Lakshmanan12%

7/24/2026, 8:12:00 AM

BS Summary: This article contains 19 faulty reasoning types, including Hasty Generalization, Overconfidence Bias, and Recency Bias, with Appeal to Authority as the most egregious example at 24.2% saturation with 292 hits. Analysis detected 1,386 faulty-reasoning hits from 1,207 analyzed words, generating a BS Score of 22.4% and a BS Rank of 6% (20,569 of 21,887 articles). This article is better (less manipulative) than 94.00% of the article peer group.

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. 
"BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet reconnaissance and malware delivery into a repeatable victim acquisition pipeline," JUMPSEC said in a detailed report shared with The Hacker News. 
"The platform profiles victims' cryptocurrency wallets before malware delivery, enabling selective targeting of high-value victims." 
Describing the campaign as an operator-driven victim acquisition platform, the cybersecurity company noted that the activity involves using compromised trusted contacts as the initial access vector to create a self-propagating attack chain via Telegram. 
Details of the activity have been documented in detail since early 2025, with Sekoia tracking a second related North Korea-aligned threat cluster under the moniker ClickFake Interview owing to the use of ClickFix-like lures to deceive unsuspecting targets into running malicious commands under the pretext of addressing camera or audio issues. 
According to JUMPSEC, the lure links are distributed from an account the target already trusts and has met in real life, with the attackers hijacking legitimate Telegram accounts of individuals in the cryptocurrency space to message high-ranking employees of major companies and share a Calendly meeting link. 
"Every victim who runs the payload with Telegram Web open or Telegram Desktop installed is a candidate for their Telegram session to be stolen and reused against their own contacts," JUMPSEC said, describing the self-sustaining nature of the campaign and how one account compromise feeds the next. 
The Calendly link takes the victim to what appears to be a Zoom meeting URL, but, in reality, is a fake domain impersonating the videoconferencing service. 
Users who land on the phishing page are prompted to enter their name and grant it permissions to access the webcam. 
However, once the permissions are provided, the webcam stream is stealthily sent to the operators' panel via mediasoup WebRTC. 
In the final stage, after the victim joins the meeting, they are shown another page where they seem to be in a Zoom call all by themselves, along with the message "waiting for other participants." 
This sets the stage for the next phase of the attack. 
"So, once the victim has joined, the operator can then continue to use their panel in order to control the meeting, send fake 'your mic isn't working' messages, and trigger the 'Zoom SDK Update,' ultimately resulting in the ClickFix payload," JUMPSEC said. 
Simultaneously, the kit executes a fingerprinting step on the web browser to inventory the cryptocurrency wallets installed on it, after which the "admin" joins the fake meeting. 
The twist here is that the video the victim sees isn't a live stream, but rather a pre-edited video that features AI-generated headshots created using OpenAI ChatGPT and superimposed over authentic body movements captured during previous meetings. 
"So, each successful attack feeds source material into the composites used against the next target," JUMPSEC explained. 
"This combined with the Telegram account takeover method means that the fake meeting shows a plausibly familiar-looking face, moving with the body language of someone who was actually captured on camera." 
The cybersecurity company said it captured two distinct lure variants, each for Zoom and Microsoft Teams. 
The Teams variant is assessed to be more polished than the Zoom version, supporting emoji reaction, mobile/tablet blocking, and advanced wallet probes prior to malware delivery. 
The ClickFix attack chains are compatible with both Windows and macOS. 
A brief description of each of them is as follows - 
Windows kill chain: 
* The ClickFix command runs a PowerShell loader that downloads and executes a VBScript, disables Microsoft Defender, adds "C:\Users" folder to the exclusion path, and force-restarts Defender so that the exclusions are applied. 
* The VBScript implant checks for the presence of Telegram Web-related files within Google Chrome, Microsoft Edge, Brave, and Mozilla Firefox profile directories, likely to determine if the victim has an active Telegram account and potentially hijack the account's session cookies in order to take control of the account and use it to target other individuals of interest. 
* The implant enumerates installed extensions across Chrome, Chrome Beta, Chrome Dev, Chromium, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox, reports their corresponding extension IDs, which are then matched against known wallet extensions like MetaMask to identify high-value targets. 
* The implant also supports the ability to deliver next-stage payloads, although their exact nature remains unknown. 
macOS kill chain: 
* The ClickFix command runs a shell script, which then downloads a fake Teams (or Zoom) installer. 
* The installer runs the main stealer payload to extract and exfiltrate sensitive data, including system metadata and Google Chrome master keys from the iCloud Keychain, to the attacker via a Telegram channel named "Aurora," and deploy additional payloads. 
Further analysis has determined that the Telegram exfiltration function hard-codes the bot token and chat ID within the stealer binary. 
Querying the Telegram API for the bot token has linked it to an operator who goes by the name "John" (@alchemy_john_mac). 
As recently as May 2026, the individual has been observed asking admins of the MAIV cryptocurrency group about vesting contracts and withdrawing their funds. 
On top of that, an examination of the threat actor infrastructure has led to the discovery of five distinct versions of the phishing kit from May 31 to July 14, 2026, indicating active development and fine-tuning efforts. 
A notable aspect of the campaign is its specific focus on lures related to Zoom and Teams, as opposed to, say, Google Meet. 
Sean Moran, head of threat research and enablement at JUMPSEC, told The Hacker News that there are three possible reasons behind this behavior: ClickFix pretext, Target-application fits, and the typosquatting surface - 
"The whole hook is the 'Zoom/Teams SDK out of date' - that only lands on platforms that victims believe have somewhat of a heavyweight desktop client (like Teams and Zoom have). 
But Google Meet doesn't have a desktop application and is browser-first, so it doesn't really make sense there. 
Zoom and Teams are the default for a lot of crypto/venture capitalist/founders in the finance world - whereas Google Meet feels more of a customer calling platform rather than an "investor/partnership call." 
The entire domain scheme being 'us.zoom.06webin.us' and such makes it really easy for someone to fall for their fake links because they are so similar to real Zoom links with all the sub-domains, whereas 'meet.google.com' is harder to typosquat/spoof." 
Moran also pointed out that while the phishing kit currently only ships Zoom and Teams lure pages, there does exist a Google Meet equivalent as an unimplemented stub in the source code. 
This, he added, is likely a deliberate choice for the above-mentioned factors and the fact that the current set up is actively working. 
"The implications extend beyond this specific campaign. 
As Web3 and digital assets continue to mature, threat actors are increasingly recognising that compromising the individuals who control access can be as valuable as attacking the infrastructure itself," JUMPSEC concluded. 
"BlueNoroff's continued refinement demonstrates that organisations must consider identity, relationships and communication channels as critical parts of their security posture." 
Article reasoning-pattern comparisonThis article: 2.8%Ravie Lakshmanan: 1.5%The Hacker News: 1.9%Confirmation Bias2.8%This article: 2.6%Ravie Lakshmanan: 1.4%The Hacker News: 1.2%Anchoring Bias2.6%This article: 5.0%Ravie Lakshmanan: 2.4%The Hacker News: 3.3%Availability Heuristic5.0%This article: 4.8%Ravie Lakshmanan: 1.7%The Hacker News: 1.5%Representativeness Heuristic4.8%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Hindsight Bias0.0%This article: 10.0%Ravie Lakshmanan: 2.4%The Hacker News: 2.5%Overconfidence Bias10.0%This article: 0.0%Ravie Lakshmanan: 2.4%The Hacker News: 2.7%Framing Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.8%The Hacker News: 1.0%Loss Aversion0.0%This article: 1.7%Ravie Lakshmanan: 0.4%The Hacker News: 0.6%Status Quo Bias1.7%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 2.6%Ravie Lakshmanan: 1.1%The Hacker News: 1.3%Optimism Bias2.6%This article: 0.0%Ravie Lakshmanan: 1.5%The Hacker News: 1.6%Pessimism Bias0.0%This article: 4.6%Ravie Lakshmanan: 7.7%The Hacker News: 6.7%Negativity Bias4.6%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 4.8%Ravie Lakshmanan: 0.6%The Hacker News: 0.4%Fundamental Attribution Error4.8%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.2%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 6.2%Ravie Lakshmanan: 2.4%The Hacker News: 1.5%Recency Bias6.2%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 2.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Ad Hominem2.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 24.2%Ravie Lakshmanan: 4.9%The Hacker News: 4.0%Appeal to Authority24.2%This article: 2.7%Ravie Lakshmanan: 0.5%The Hacker News: 1.6%False Dilemma2.7%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Circular Reasoning0.0%This article: 16.5%Ravie Lakshmanan: 4.0%The Hacker News: 4.3%Hasty Generalization16.5%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.2%Bandwagon0.0%This article: 0.0%Ravie Lakshmanan: 1.1%The Hacker News: 1.1%Appeal to Emotion0.0%This article: 2.8%Ravie Lakshmanan: 0.2%The Hacker News: 0.5%Begging the Question2.8%This article: 5.9%Ravie Lakshmanan: 2.1%The Hacker News: 1.9%Post Hoc (False Cause)5.9%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%No True Scotsman0.0%This article: 5.7%Ravie Lakshmanan: 3.8%The Hacker News: 2.3%Ambiguity (Equivocation)5.7%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 5.9%Ravie Lakshmanan: 3.4%The Hacker News: 1.4%Unattributed Quote5.9%This article: 0.0%Ravie Lakshmanan: 2.6%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 0.0%Ravie Lakshmanan: 2.5%The Hacker News: 2.3%Biased Writer Voice0.0%This article: 4.2%Ravie Lakshmanan: 2.4%The Hacker News: 4.4%Indoctrination4.2%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

1207 words analyzed.

Speakers

2speakers34%attributed speech795writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 10 words • 0.0% coverageWriter's voice • 39 words • 0.0% coverageJUMPSEC • 34 words • 100.0% coverageJUMPSEC • 15 words • 0.0% coverageWriter's voice • 34 words • 0.0% coverageWriter's voice • 51 words • 0.0% coverageWriter's voice • 47 words • 0.0% coverageJUMPSEC • 47 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 35 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageJUMPSEC • 42 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 37 words • 100.0% coverageJUMPSEC • 17 words • 0.0% coverageJUMPSEC • 31 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 33 words • 0.0% coverageWriter's voice • 58 words • 0.0% coverageWriter's voice • 40 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 39 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 37 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageSean Moran • 32 words • 0.0% coverageSean Moran • 31 words • 0.0% coverageSean Moran • 18 words • 0.0% coverageSean Moran • 32 words • 0.0% coverageSean Moran • 39 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageSean Moran • 23 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageJUMPSEC • 31 words • 100.0% coverageJUMPSEC • 20 words • 100.0% coverage
Selected voice

JUMPSEC

100%flagged-word coverage
237 attributed words58% of attributed speech31% writer coverage
0%12.5%25.0%Indoctrination+21.5 ptsWriter: 0.0%JUMPSEC: 21.5%21.5%Unattributed Quote+9.7 ptsWriter: 4.7%JUMPSEC: 14.3%14.3%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.