>samit_hota
Back to security news
SN-2026-185HighOpen

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Prior to Malware Delivery

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Zoom, Microsoft Teams, Cryptocurrency Holders, Web3 Organizations
#news#phishing-social-engineering#bluenoroff

North Korea’s state-sponsored BlueNoroff group has escalated its financial cyber operations by deploying a custom Zoom phishing kit engineered to inspect browser environment data before dropping malicious payloads. Operating through typosquatted videoconferencing domains, the campaign targets cryptocurrency organizations and high-value Web3 individuals through ClickFix-style social engineering lures.

Wallet Profiling Before Payload Delivery

BlueNoroff—a distinct threat subgroup within the broader Lazarus Group ecosystem—has refined its initial access tradecraft to ensure it only deploys custom malware against high-yield targets. The newly identified phishing kit impersonates online meeting software, specifically Zoom and Microsoft Teams, using compromised industry contacts and lookalike domains to build trust with victims.

Before executing any malicious scripts or delivering malware payloads, the phishing kit conducts active fingerprinting of the target’s web browser environment. It scans specifically for the presence of web3 browser extensions and cryptocurrency wallet signatures (such as MetaMask, Coinbase Wallet, and Phantom). By checking active extension IDs and local storage indicators, the infrastructure determines the target’s financial potential. If the target does not meet specific criteria, the kit halts the attack chain, frustrating automated sandbox analysis and security research attempts.

Overlap with ClickFix Social Engineering

The social engineering vector leverages the “ClickFix” execution technique, which has gained popularity across multiple threat actor groups over the past year. Victims expecting a legitimate business call or investor meeting are invited to join a conference room link hosted on a typosquatted domain.

Upon navigating to the spoofed meeting page, the site displays a fake error popup indicating an issue with the user’s audio or video driver. The victim is instructed to resolve the issue by copying a provided terminal string or PowerShell command and running it directly in their operating system’s command terminal. This tricks the user into manually executing a malicious loader, bypassing standard web browser download warnings and initial security controls.

Countermeasures for Web3 and Enterprise Teams

Defending against targeted social engineering campaigns from threat actors like BlueNoroff requires combination control strategies across browser defense and command monitoring:

  • Restrict Browser Extension Footprints: Educate personnel handling cryptocurrency operations to utilize dedicated, hardened browser profiles or separate hardware endpoints for web browsing and wallet management to prevent extension profiling.
  • Monitor Process Spawn Patterns: Configure Endpoint Detection and Response (EDR) rules to detect manual command-line invocations—such as powershell.exe or cmd.exe—that contain encoded payloads or download strings executed shortly after web browser interactions.
  • Implement Strict Domain Blocking: Ingest threat intelligence feeds covering typosquatted videoconferencing domains and block newly registered domains containing keywords related to Zoom, Microsoft Teams, and Web3 platforms.
  • Use Hardware Storage for Digital Assets: Maintain high-value assets in multi-signature cold storage configurations or hardware wallets rather than active browser extension wallets.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call