North Korea’s notorious hacking group BlueNoroff has been using fake Zoom and Microsoft Teams calls to target crypto wallet owners worldwide. Security firm JUMPSEC exposed the scheme, revealing that the attackers scan victims’ browsers during these calls to identify valuable cryptocurrency wallets before deploying malware selectively.
The operation has already affected over 100 individuals across more than 20 countries, with 41% of victims based in the United States. Nearly half of the targets are founders or CEOs, highlighting the attackers’ focus on high-value profiles. The hackers cleverly exploit trust by hijacking Telegram accounts of crypto contacts to send fake meeting invitations, widening their reach.
Advanced Wallet Profiling and Malware Deployment
JUMPSEC’s analysis uncovered that BlueNoroff actively tracks Ethereum wallets using the EIP-6963 standard and legacy browser methods, as well as non-EVM wallets like Solana. This data feeds into an operator dashboard, allowing hackers to decide which wallets warrant a full-scale breach. The malware supports multiple browsers, including Chrome, Edge, Brave, Opera, Vivaldi, and Firefox, by checking for known crypto wallet extensions such as MetaMask.
During the fake video calls, victims are prompted to provide their names and webcam access, which is secretly streamed to the attackers. The phishing kit’s source code was recovered after operators mistakenly left JavaScript source maps exposed, revealing the inner workings of the scam between April and July 2026.
This campaign is part of BlueNoroff’s evolving phishing toolkit, with JUMPSEC identifying four new macOS variants in recent months. The group operates under the larger Lazarus umbrella, notorious for high-profile cyberattacks and crypto thefts.



