"BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet reconnaissance and malware delivery into a repeatable victim acquisition pipeline," JUMPSEC said.
JUMPSEC: a repeatable victim-acquisition platform
Cybersecurity firm JUMPSEC describes a sophisticated, operator-driven campaign tied to North Korea-aligned BlueNoroff that marries social engineering with technical reconnaissance. The campaign uses hijacked trusted contacts, carefully crafted videoconferencing lures, and an active phishing kit that profiles victims' cryptocurrency wallets before delivering malware, a combination the company says enables "selective targeting of high-value victims."
JUMPSEC's analysis, shared with The Hacker News, lays out a multi-stage pipeline running since early 2025 and actively refined through mid-2026. The report documents how compromised relationships and messaging channels are weaponised to create a self-propagating attack chain that feeds new victims into the same system.
Telegram-based trust abuse and self-propagation
The attackers begin by hijacking legitimate Telegram accounts of individuals in the cryptocurrency space and using those accounts to message high-ranking employees at major companies. Lures include Calendly meeting links that resolve to typosquatted Zoom or Microsoft Teams domains rather than legitimate conferencing services.
JUMPSEC noted a particularly corrosive feedback loop: "Every victim who runs the payload with Telegram Web open or Telegram Desktop installed is a candidate for their Telegram session to be stolen and reused against their own contacts." That stolen session then becomes the vector to send more Calendly links and lure additional victims, producing a self-sustaining propagation mechanism via Telegram.
Wallet reconnaissance and AI-generated composite video
While the victim is interacting with the fake conferencing page, the phishing kit performs browser fingerprinting to inventory installed cryptocurrency wallet extensions. Extension IDs are matched against known wallet extensions such as MetaMask so that the operator can identify high-value targets prior to deploying malware.
Concurrently, the page requests webcam permissions and streams the captured video to an operator panel using mediasoup WebRTC. When the victim joins what appears to be a meeting, they see a pre-edited video rather than a live feed. JUMPSEC said attackers create AI-generated headshots using OpenAI ChatGPT and composite them over authentic body movements captured in past meetings so that the face and movement appear plausibly familiar. "So, each successful attack feeds source material into the composites used against the next target," JUMPSEC wrote.
Sean Moran, head of threat research and enablement at JUMPSEC, explained why Zoom and Teams are the primary lures: the ClickFix pretext ("Zoom/Teams SDK out of date") makes sense for heavyweight desktop clients, those platforms are common among crypto and finance professionals, and their URL structures are easier to typosquat than browser-first meet alternatives. Moran added that a Google Meet equivalent exists as an unimplemented stub in the kit's source code.
Windows and macOS kill chains
JUMPSEC detailed distinct kill chains for Windows and macOS that complete the operator's pipeline.
- Windows: The ClickFix command runs a PowerShell loader that downloads and executes a VBScript, disables Microsoft Defender, adds the "C:\Users" folder to Defender's exclusion path and force-restarts the service. The VBScript then checks for Telegram Web-related files in browser profile folders, enumerates installed browser extensions across many Chromium-based and Firefox browsers, and reports extension IDs that are cross-referenced against wallet extensions. The implant can also deliver additional next-stage payloads.
- macOS: The ClickFix command launches a shell script that downloads a fake Teams or Zoom installer. The installer runs a stealer payload that exfiltrates system metadata and Chrome master keys from the iCloud Keychain to the attackers via a Telegram channel named "Aurora" and deploys further payloads. The stealer binary hard-codes a Telegram bot token and chat ID; querying the Telegram API linked the bot token to an operator calling themselves "John" (@alchemy_john_mac), who as recently as May 2026 engaged with admins of the MAIV cryptocurrency group about vesting contracts and withdrawing funds.
Active development, operator signals, and operational choices
Analysis of the attacker infrastructure uncovered five distinct versions of the phishing kit between May 31 and July 14, 2026, indicating active development and refinement. JUMPSEC highlighted that the Teams variant is more polished than the Zoom variant, offering emoji reaction support, mobile/tablet blocking, and advanced wallet probes prior to malware delivery.
The campaign's specific focus on Zoom and Teams — rather than other conferencing platforms — is intentional, JUMPSEC says, driven by the pretext that only client-based SDKs fit the ClickFix ruse, the target audience's platform preferences, and the ease of typosquatting those services' links.
What this means for technologists, enterprises, and end users
- Technologists and security teams: JUMPSEC's findings show that identity and communications channels are attack surfaces; defenders will need to consider account compromise and session theft vectors in addition to traditional malware detection.
- Affected enterprises and procurement leaders: The campaign demonstrates targeted reconnaissance on browser wallet extensions and selective targeting of high-value individuals — procurement and risk teams should note that attackers are choosing victims before delivering payloads.
- End users and the general public: Compromised Telegram sessions can be reused to target personal contacts, so users who rely on Telegram Web or Desktop are specifically at risk of having their sessions stolen and their contacts socially engineered.
BlueNoroff's phishing kit links social trust, profile reconnaissance and automated malware delivery into a loop that feeds itself. As JUMPSEC concluded, "BlueNoroff's continued refinement demonstrates that organisations must consider identity, relationships and communication channels as critical parts of their security posture."
Original reporting: https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html




