North Korea’s state-sponsored BlueNoroff group has escalated its financial cyber operations by deploying a custom Zoom phishing kit engineered to inspect browser environment data before dropping malicious payloads. Operating through typosquatted videoconferencing domains, the campaign targets cryptocurrency organizations and high-value Web3 individuals through ClickFix-style social engineering lures.
Wallet Profiling Before Payload Delivery
BlueNoroff—a distinct threat subgroup within the broader Lazarus Group ecosystem—has refined its initial access tradecraft to ensure it only deploys custom malware against high-yield targets. The newly identified phishing kit impersonates online meeting software, specifically Zoom and Microsoft Teams, using compromised industry contacts and lookalike domains to build trust with victims.
Before executing any malicious scripts or delivering malware payloads, the phishing kit conducts active fingerprinting of the target’s web browser environment. It scans specifically for the presence of web3 browser extensions and cryptocurrency wallet signatures (such as MetaMask, Coinbase Wallet, and Phantom). By checking active extension IDs and local storage indicators, the infrastructure determines the target’s financial potential. If the target does not meet specific criteria, the kit halts the attack chain, frustrating automated sandbox analysis and security research attempts.
Overlap with ClickFix Social Engineering
The social engineering vector leverages the “ClickFix” execution technique, which has gained popularity across multiple threat actor groups over the past year. Victims expecting a legitimate business call or investor meeting are invited to join a conference room link hosted on a typosquatted domain.
Upon navigating to the spoofed meeting page, the site displays a fake error popup indicating an issue with the user’s audio or video driver. The victim is instructed to resolve the issue by copying a provided terminal string or PowerShell command and running it directly in their operating system’s command terminal. This tricks the user into manually executing a malicious loader, bypassing standard web browser download warnings and initial security controls.
Countermeasures for Web3 and Enterprise Teams
Defending against targeted social engineering campaigns from threat actors like BlueNoroff requires combination control strategies across browser defense and command monitoring:
- Restrict Browser Extension Footprints: Educate personnel handling cryptocurrency operations to utilize dedicated, hardened browser profiles or separate hardware endpoints for web browsing and wallet management to prevent extension profiling.
- Monitor Process Spawn Patterns: Configure Endpoint Detection and Response (EDR) rules to detect manual command-line invocations—such as
powershell.exeorcmd.exe—that contain encoded payloads or download strings executed shortly after web browser interactions. - Implement Strict Domain Blocking: Ingest threat intelligence feeds covering typosquatted videoconferencing domains and block newly registered domains containing keywords related to Zoom, Microsoft Teams, and Web3 platforms.
- Use Hardware Storage for Digital Assets: Maintain high-value assets in multi-signature cold storage configurations or hardware wallets rather than active browser extension wallets.
Related content
Enterprise AI Adoption Triggers 685% Surge in SOC Noise and Brand Impersonation
Security NewsForg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
Security NewsGreatness PhaaS Adds Device Code Phishing to Bypass MFA and Hijack Accounts
Security NewsGreatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call