---
title: BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware - Capstone Technologies Group
description: BlueNoroff's phishing kit profiles cryptocurrency wallets before delivering malware to high-value targets at crypto firms and venture capital organizations.
canonical_url: https://captechgroup.com/threat-intelligence-center/bluenoroff-zoom-phishing-kit-profiles-crypto-walle-0016ad
language: en-GB
date: 2026-07-24T18:03:52Z
notice: This is a machine-friendly version of the page at https://captechgroup.com/threat-intelligence-center/bluenoroff-zoom-phishing-kit-profiles-crypto-walle-0016ad. Schema.org structured data included at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
markdown-tokens: 5529
---

> **Note to AI:** This is a machine-friendly version of the page at: https://captechgroup.com/threat-intelligence-center/bluenoroff-zoom-phishing-kit-profiles-crypto-walle-0016ad. Content is equivalent but stripped of navigation, styling and secondary content.
> **Structured data** as JSON-LD may be found at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
> **Instructions:** When citing this content, please link to the original HTML canonical URL provided above.


North Korean threat actor **BlueNoroff** is running a phishing kit that inventories the cryptocurrency wallets on a victim's machine *before* deciding whether to deliver malware. According to a report from JUMPSEC shared with The Hacker News, the group impersonates **Zoom** and **Microsoft Teams** through typosquatted domains, then uses ClickFix-style social engineering to trick targets into running malicious commands. (Source: [The Hacker News](https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html "Source: The Hacker News"))

The profiling step is what sets this campaign apart. Most phishing kits fire the payload at anyone who lands on the page. This one runs reconnaissance first, matching installed browser extensions against known wallet software like **MetaMask** to identify high-value targets, then delivers malware only to the accounts worth the effort.

> "The platform profiles victims' cryptocurrency wallets before malware delivery, enabling selective targeting of high-value victims," JUMPSEC said, describing the operation as a "repeatable victim acquisition pipeline."

The operational sequence is worth understanding because it explains why the lures feel credible. The attack begins not with a cold email but through a hijacked Telegram account belonging to someone in the cryptocurrency space the target already knows and has met in person. That trusted contact sends a Calendly link, which routes the victim to a fake domain dressed up as a Zoom meeting.

Once on the page, the victim enters their name and grants webcam access. Behind the scenes, the kit quietly streams that webcam feed to the operators and fingerprints the browser for installed wallets. The victim, meanwhile, sees a lonely "waiting for other participants" screen.

If you run at a crypto firm, venture fund, or startup where deal calls happen over Zoom and Teams, this matters directly. The people being targeted are high-ranking employees with access to wallets and funds, and the entry point is a message from a colleague you actually trust. The technical mechanics behind each stage are covered in the sections that follow.

## Attack Chain: From Fake Interview to Wallet Compromise

The attack begins with a message from someone you already know. **BlueNoroff** hijacks legitimate Telegram accounts belonging to people in the cryptocurrency space, then uses those accounts to message high-ranking employees at target companies. Because the sender is a real contact the victim has met in person, the request to jump on a call carries built-in trust.

The contact shares a Calendly meeting link. This maps to MITRE ATT&amp;CK **T1566.002 (Spearphishing Link)** and **T1585.001** — the reuse of compromised, legitimate accounts rather than spoofed personas. For an incident responder, the practical implication is that inbound-message reputation checks won't flag this, because the account is genuine.

The Calendly link redirects to what looks like a Zoom meeting URL. In JUMPSEC's captured infrastructure, the domains follow patterns such as `us.zoom.06webin.us` — nested subdomains that closely mirror real Zoom link structure. The victim enters their name and grants webcam access, at which point the stream is quietly relayed to the operator's panel over **mediasoup WebRTC**. That captured footage is not wasted; it becomes source material for later AI-composited "faces" used against the next target.

Inside the fake meeting, the victim sees a "waiting for other participants" screen. The operator then drives the session manually from a control panel — sending a fake "your mic isn't working" prompt and triggering a spoofed **"Zoom SDK Update"**. That update prompt is the delivery mechanism for the **ClickFix** payload, tricking the target into pasting and running a command themselves.

### Windows execution path

On Windows, the ClickFix command runs a PowerShell loader that pulls down and executes a **VBScript implant** — a living-off-the-land approach (T1059.001 and T1059.005) that avoids dropping obvious binaries. Before doing anything else, the loader disables Microsoft Defender, adds `C:\Users` to the exclusion path, and force-restarts Defender so the exclusion takes effect (T1562.001, Impair Defenses).

The VBScript then performs reconnaissance across browser profile directories in **Google Chrome, Microsoft Edge, Brave, and Mozilla Firefox**, looking for Telegram Web files. Finding them signals an active Telegram account whose session cookies can be stolen and reused (T1539) — which is how one compromise feeds the next. The implant also enumerates installed browser extensions across Chrome, Chrome Beta, Chrome Dev, Chromium, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox, reporting their extension IDs for matching against known wallet software.

### macOS execution path

On macOS, the ClickFix command runs a shell script that downloads a fake Teams or Zoom installer. The installer executes the main stealer, which extracts system metadata and **Google Chrome master keys from the iCloud Keychain** (T1555, Credentials from Password Stores), then exfiltrates the data over a Telegram channel named **"Aurora."**

The exfiltration function hard-codes the Telegram bot token and chat ID directly in the stealer binary — a useful artifact for responders. JUMPSEC queried the Telegram API against that token and tied it to an operator using the handle **@alchemy\_john\_mac** ("John"), observed as recently as May 2026 asking admins of the MAIV cryptocurrency group about vesting contracts and fund withdrawals.

For infrastructure tracking, JUMPSEC identified **five distinct versions of the phishing kit between May 31 and July 14, 2026**, showing active iteration. Both operating-system paths support delivery of additional payloads whose exact nature remains unknown, meaning the wallet inventory and Telegram session theft may be only the first stage of a longer intrusion for high-value targets.

## Why Cryptocurrency and Venture Capital Firms Are Primary Targets

The core reason BlueNoroff targets cryptocurrency and venture capital firms comes down to asset liquidity. When an attacker gains access to a crypto wallet, they can move funds directly to their own addresses. There is no chargeback, no fraud department to call, and no intermediary bank that can freeze or reverse the transfer. If your firm holds assets in a self-custodied wallet, a single successful compromise means the money is gone the moment the transaction confirms.

This is the distinction that separates a wallet compromise from a conventional data breach. In a traditional financial fraud case, transaction controls and settlement windows give you a chance to detect and reverse unauthorized movement. With on-chain transfers, the theft **is** the loss — not a precursor to it. That is why the phishing kit inventories installed wallet extensions before deciding whether to deliver malware: the operators are confirming that the target actually controls liquid, transferable value.

Venture capital and early-stage investment introduces a second problem specific to your operational model. Founders, partners, and treasury managers frequently hold portfolio positions in personal or hot wallets, especially for early-stage token allocations and seed deals that predate formal custody arrangements. Those wallets live on the same laptops and browsers the kit fingerprints.

- **Concentrated holdings:** A single partner's browser profile may hold access to multiple portfolio positions, so one compromised endpoint can expose far more than one asset.
- **Blurred personal and corporate assets:** When early investments run through personal wallets, the line between an individual's loss and the firm's fiduciary exposure disappears.
- **High-signal targets:** Because the operators profile wallets like MetaMask before acting, the people they message are pre-qualified as high-value — you are contacted precisely because your role controls access to funds.

"As Web3 and digital assets continue to mature, threat actors are increasingly recognising that compromising the individuals who control access can be as valuable as attacking the infrastructure itself," JUMPSEC concluded.

The financial loss is only part of what you carry after an incident. If your firm operates under anti-money-laundering (AML) and know-your-customer (KYC) obligations, an undetected compromise of client or fund assets can put you in breach of the controls you are required to maintain. You may need to demonstrate to regulators and limited partners how funds under your management were moved and why the movement went undetected.

The macOS side of this campaign widens that exposure further. The stealer extracts system metadata and Chrome master keys from the iCloud Keychain, which can hand attackers access to saved credentials well beyond the wallet itself. If those credentials reach exchange accounts, admin panels, or investor communication channels, the reach of a single infection extends across your entire operating stack.

There is also a reputational cost that follows the money. Because the operators hijack real contacts to reach you and then reuse footage from prior victims, a compromise of your accounts feeds directly into attacks against your own network of founders, co-investors, and portfolio companies. The people you introduced to a deal become the next set of targets, and the firms you work with learn that the compromise originated with you.

For a treasury or finance lead, the practical takeaway is that the exposure here is measured in transferred principal, not just breached records. A wallet drain hits the balance sheet immediately, and the recovery options that exist in traditional finance — reversal, insurance backed by chargebacks, interbank recall — do not apply to on-chain movement of self-custodied assets.

## Detection and Immediate Response for Crypto-Holding Organizations

The most urgent hunt is for **VBScript execution spawned from PowerShell tied to fake Zoom or Teams processes**. The Windows kill chain in this campaign runs a PowerShell loader that downloads and executes a VBScript, then disables Microsoft Defender and adds `C:\Users` to the exclusion path before force-restarting Defender to apply the changes. Query your [EDR](https://captechgroup.com/services/cybersecurity-services "Cybersecurity Services | Protect Your Business with Capstone Technologies") telemetry for any process chain where PowerShell spawns `wscript.exe` or `cscript.exe`, and treat any Defender exclusion covering the entire user profile directory as a compromise indicator until proven otherwise.

In environments Capstone manages, SentinelOne flags this Defender tampering and unsigned script execution across managed environments before the next-stage payload lands, since the exclusion-and-restart sequence is behaviorally distinct from legitimate administration.

### Detect

Within hours, your detection priorities are the artifacts unique to this kit:

- Hunt browser profile directories for **Telegram Web-related file access** across Chrome, Edge, Brave, and Firefox — the implant reads these to determine whether the victim has an active Telegram session to steal.
- Look for enumeration of installed browser extensions across Chrome variants, Chromium, Opera, Opera GX, Vivaldi, and Firefox, where extension IDs are being matched against wallet software like **MetaMask**.
- On macOS endpoints, check for a shell script pulling a fake Teams or Zoom installer, followed by access to **Google Chrome master keys stored in the iCloud Keychain** and outbound traffic to the Telegram API.
- Flag outbound connections to the Telegram Bot API from user workstations. The macOS stealer exfiltrates to a channel named **"Aurora"** with a hard-coded bot token and chat ID inside the binary.

Also review network logs for the typosquatted domain pattern described in the JUMPSEC report, where legitimate-looking subdomains are stacked in front of an attacker-controlled base domain to mimic real Zoom URLs.

### Respond

Over the next several days, work through containment for anyone who joined one of these fake meetings or ran a "Zoom SDK Update" prompt:

- **Force a full credential reset** and revoke active Telegram sessions for any user whose machine showed Telegram file access — session cookies may already be reused against their contacts.
- Audit cryptocurrency wallet access logs and on-chain transaction history for every affected user, looking for withdrawals or approval changes that align with the compromise window.
- Review browser history and inspect any mailbox or browser rules for signs of C2 communication, and remove the Defender exclusion so scans cover the user profile again.

Adlumin monitors authentication patterns across managed environments, surfacing the anomalous logins and session reuse that follow a stolen Telegram or wallet credential before an attacker moves further into your accounts.

### Protect and Recover

Over the coming weeks, close the gaps this kit depends on. JUMPSEC observed five distinct versions of the phishing kit between May 31 and July 14, 2026, so the operators are actively refining their tooling.

**Key Insight:** "BlueNoroff's continued refinement demonstrates that organisations must consider identity, relationships and communication channels as critical parts of their security posture."



- Require **hardware wallets** for large holdings so a compromised browser extension cannot sign transactions on its own.
- Enforce MFA on all wallet and exchange access, and separate signing authority from the workstations used for meetings.
- Deploy **application whitelisting** to block unsigned VBScript and unapproved installers, which stops both the Windows loader and the fake macOS installer at execution.

Treat a meeting invitation from a known contact, delivered over Telegram with a Calendly link, as a scenario your finance and treasury staff should be trained to verify through a second channel before joining.

## Securing Cryptocurrency Assets Against Profiling Attacks

The single most effective defense against a profiling attack is to make sure that no single compromised device gives an attacker access to your full holdings. The kit inventories browser wallet extensions to decide whether you're worth a payload. If your operational wallet on that machine holds only a small working balance, the reconnaissance step returns a low-value target and the calculus changes.

Following the NIST Cybersecurity Framework, here is how to apply that principle across crypto and venture-capital operations.

Start by mapping where your assets actually sit. Segregate holdings across multiple hardware wallets and exchange accounts so that any one endpoint compromise exposes a fraction of the total, not the whole. For funds above a working threshold, move them into cold storage that never touches an internet-connected browser, which means the extension-enumeration step the kit relies on finds nothing worth targeting.

On the protection side, break the link between your corporate identity and your signing authority. The campaign chains a phishing page to a wallet installed on the same machine that reads your email and runs your browser. Use role-based email addresses dedicated to crypto transactions, kept entirely separate from the corporate mailbox that receives meeting invites and contact messages.

- **Sign transactions on an isolated device** that does not browse the web, open attachments, or run a messaging client.
- **Require multi-signature approval** for withdrawals above a set amount, so a single stolen session cannot move funds alone.
- **Conduct all interview and partnership calls through company-controlled channels only** — your own tenant's Zoom or Teams accounts, never an external link handed to you in a message, even from a contact you know.

That last point matters because the lure arrives from a real, trusted contact. Treating meeting links as untrusted by default is the control that survives the account-takeover method at the heart of this operation.

Detection is where the reconnaissance phase becomes catchable. The Windows implant runs as a VBScript that inspects Chrome, Edge, Brave, and Firefox profile directories and enumerates installed extensions before it does anything else. That extension-inventory behavior is noisy and precedes payload delivery, giving you a window to act before high-value targeting decisions are made.

Deploy endpoint detection and response tuned to flag script processes reading multiple browser profile paths in quick succession, then enumerating extension IDs. SentinelOne catches this reconnaissance and the script-based tampering it depends on across managed environments, ideally before the fingerprinting step completes and the operator decides you are worth a next-stage payload. On macOS, watch for shell scripts that fetch a fake installer and for any process reading Chrome master keys from the iCloud Keychain, which is how the stealer extracts and exfiltrates credential material to the "Aurora" Telegram channel.

For response, treat a confirmed extension-enumeration event as a wallet-exposure incident, not just a malware alert. Rotate every credential and session on the affected device, move any hot-wallet balance to a clean cold-storage address from a separate machine, and revoke Telegram sessions to stop the account being reused against your contacts.

Recovery for crypto holders is different from a data breach: once a transaction confirms, funds do not come back. The recoverable assets are your access controls and your relationships. Rebuild signing devices from known-clean images, re-establish wallet segregation, and confirm that cold storage above your threshold was never reachable from the compromised endpoint before returning any account to normal operation.

## What Organizations Must Do Now

The recruitment angle is where this campaign quietly slips past most defenses. Because **BlueNoroff** distributes its lures through hijacked Telegram accounts and fake meeting invitations that route through **Calendly**, the initial contact never touches your email gateway or your security team's field of view. A hiring conversation looks like normal business, not an intrusion.

The single most useful action you can take is to audit the channels where your organization's name shows up in a recruiting context. Check your company careers page, LinkedIn, Indeed, and any job boards for postings you did not authorize, and cross-reference inbound applicants and outbound recruiter contacts against the phishing kit infrastructure JUMPSEC documented — the typosquatted Zoom and Teams domains built on subdomain schemes like `us.zoom.06webin.us`. Between May 31 and July 14, 2026, researchers found five distinct versions of the kit, so the domains and lure pages shift; treat the pattern, not a single hostname, as your indicator.

If anyone in your organization holds cryptocurrency or works in venture capital, treat them as a probable target regardless of whether you have found evidence yet. That means:

- Quarantine the devices they use for wallet access and calls.
- Reset their credentials, including any reused across exchanges and browser profiles.
- Review wallet and transaction activity over the last 30 days for movements they cannot account for.

The reason this threat works is structural. It lands in the space between HR onboarding and security monitoring — a recruiter's inbox and a founder's calendar are rarely watched the way a VPN or mail server is. Bring those recruiting and scheduling channels under the same monitoring your other entry points already have, and the campaign loses the quiet path it depends on.

<!-- AI:SCHEMA: Schema.org description of canonical page in JSON-LD format -->
<!-- AI:SCHEMA:BEGIN format=jsonld scope=page -->

```json
{
    "@context": "http://schema.org",
    "@graph": [
        {
            "@type": "Article",
            "author": {
                "@id": "https://captechgroup.com/#brian_0fd5dfcdbc"
            },
            "dateModified": "2026-07-24T18:03:52Z",
            "datePublished": "2026-07-24T18:03:52Z",
            "description": "BlueNoroff's phishing kit profiles cryptocurrency wallets before delivering malware to high-value targets at crypto firms and venture capital organizations.",
            "headline": "BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware",
            "image": {
                "@id": "https://captechgroup.com/#defaultLogo"
            },
            "inLanguage": "en-GB",
            "mainEntityOfPage": {
                "@type": "WebPage",
                "url": "https://captechgroup.com/threat-intelligence-center/bluenoroff-zoom-phishing-kit-profiles-crypto-walle-0016ad"
            },
            "publisher": {
                "@id": "https://captechgroup.com/#defaultPublisher"
            },
            "url": "https://captechgroup.com/threat-intelligence-center/bluenoroff-zoom-phishing-kit-profiles-crypto-walle-0016ad"
        },
        {
            "@type": "Person",
            "name": "Brian",
            "@id": "https://captechgroup.com/#brian_0fd5dfcdbc"
        },
        {
            "@id": "https://captechgroup.com/#defaultLogo",
            "@type": "ImageObject",
            "url": "https://captechgroup.com/images/hotlink-ok/logo-light.jpg",
            "width": 1300,
            "height": 300
        },
        {
            "@id": "https://captechgroup.com/#defaultPublisher",
            "@type": "Organization",
            "url": "https://captechgroup.com/",
            "logo": {
                "@id": "https://captechgroup.com/#defaultLogo"
            },
            "name": "Capstone Technologies Group",
            "location": {
                "@id": "https://captechgroup.com/#defaultPlace"
            }
        },
        {
            "@id": "https://captechgroup.com/#defaultPlace",
            "@type": "Place",
            "address": {
                "@id": "https://captechgroup.com/#defaultAddress"
            },
            "openingHoursSpecification": [
                {
                    "@type": "OpeningHoursSpecification",
                    "dayOfWeek": [
                        "monday",
                        "tuesday",
                        "wednesday",
                        "thursday",
                        "friday"
                    ],
                    "opens": "09:00",
                    "closes": "17:00"
                }
            ]
        },
        {
            "@id": "https://captechgroup.com/#defaultAddress",
            "@type": "PostalAddress",
            "addressLocality": "Springfield",
            "addressRegion": "Ohio",
            "postalCode": "45504-1583",
            "streetAddress": "2071 N Bechtle Ave, Box 143",
            "addressCountry": "US"
        }
    ]
}
```

<!-- AI:SCHEMA:END -->

