BlueNoroff: a Zoom kit tailored for crypto, with live AI deepfake video

Cybersecurity 22 h agoAdd to bookmarks

BlueNoroff: a Zoom kit tailored for crypto, with live AI deepfake video
Illustration : Momiji Shirogane

The North Korean group BlueNoroff (Lazarus) has been operating a Zoom/Teams phishing kit since May 2026 that compromises legitimate Telegram accounts, invites targets to a fake meeting, captures their webcam, overlays an AI deepfake (ChatGPT), profiles installed crypto wallets, and then pushes malware via ClickFix. Five versions of the kit documented by JUMPSEC.

The facts

Publication JUMPSEC on July 24, 2026: the BlueNoroff group - a subset of Lazarus, attributed to North Korea and long specialized in the theft of digital assets - has been operating since at least May 2026 a very targeted Zoom/Teams phishing kit, with at least five versions documented between May 31 and July 14, 2026.

Targets: high-profile individuals in the crypto industry - venture capitalists, founders, executives of major Web3 companies. The kit profiles the victims' walletsbefore pushing the malware, allowing selective targeting of "high-value victims" who carry their own funds or sign transfers.

Analysis - the attack chain

It deserves to be detailed step by step because it combines several modern primitives (email account compromise, video deepfake, ClickFix) that were previously seen separately.

  1. Initial vector: compromised Telegram accounts. BlueNoroff sends a Calendly link from the account of a real contact in the crypto industry that the victim knows. Inherited trust, no alert.
  2. Trap meeting. The link leads to a typosquatted domain, imitating Zoom or Teams - documented example: us.zoom.06webin.us.
  3. Webcam capture. The site requests camera access. The victim accepts. The video stream is silently exfiltrated to the operator's panel via mediasoup WebRTC.
  4. Video deepfake overlay. The operator displays a fake head generated by AI to the target - the images are produced with ChatGPT (OpenAI) - overlaid on the body movements of a previously authenticated victim. The human on the other end sees what they believe to be their legitimate interlocutor in the video.
  5. Wallet profiling. The kit runs a browser fingerprint that lists the crypto wallet extensions installed (MetaMask, Phantom, Coinbase Wallet, etc.). This step conditions the rest: without a valuable wallet, the campaign stops there.
  6. ClickFix payload. The operator triggers a fake update pop-up - the ClickFix technique that pushes the user to copy-paste a command into their terminal or Windows Run - and the malware executes.

Observed payloads

Windows:

  • PowerShell Loader that disables Microsoft Defender.
  • VBScript implants that steal Telegram session cookies and wallet extension IDs to allow the operator to replay the Telegram session (and thus compromise the victim's contacts in turn, closing the kit's loop).

macOS:

  • Fake Teams / Zoom installers.
  • Exfiltration of Chrome master keys (necessary to decrypt Chrome credentials, including exchange logins) via the Telegram "Aurora" channel controlled by the operator.

IOCs to monitor

  • Telegram operator bot identified by JUMPSEC: @alchemy_john_mac (username "John").
  • Typosquatted Zoom/Teams domains in .us (observed pattern: us.zoom.<word>.us).
  • Outgoing WebRTC (mediasoup) traffic to unknown IPs during non-standard videos.
  • New Telegram sessions from an IP geographically inconsistent with the user.

Who is impacted

  • Anyone operating a valuable crypto wallet (VCs, founders, exchange operators, custodians).
  • By extension: their professional circles whose compromised Telegram account will serve as an upstream vector.

This is not a mass public threat: it's high-value targeted spear-phishing, with a very high ROI for the operator.

What to do now

  1. Never validate a crypto meeting based solely on a Telegram Calendly link - even if sent by a known contact. Verify on an out-of-band channel (phone, verified Signal).
  2. Video URL: check the domain letter by letter. A legitimate Zoom is zoom.us or <subdomain>.zoom.us, never zoom.<other-tld>.
  3. Separate the machine that touches your crypto wallets from the machine where you do your videos. Wallets on a dedicated machine or hardware wallet.
  4. Telegram sessions: regularly revoke active sessions (Settings → Devices) and enable local passcode.
  5. Hunt IOCs: on your EDR, hunt any VBScript implant hooking Telegram, and any programmatic disabling of Defender via PowerShell.
  6. ClickFix awareness: train your teams - copying and pasting a command from a browser into your terminal is the action never to take, even "just to finish an install".

What to do now - the essentials

Out-of-band verification of any crypto meeting initiated via Telegram + dedicated wallets machine + Telegram session revocation. The kit is active, versioned, industrialized.

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

8 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information