BlueNoroff’s: How Crypto Wallets Are Targeted via Telegram

North Korean state-sponsored threat actors, specifically the BlueNoroff group, have significantly escalated their social engineering operations against high-value targets in the cryptocurrency and financial sectors. The adversary operates a self-propagating victim acquisition pipeline that begins with hijacking legitimate Telegram accounts of industry contacts.

Using these compromised, trusted profiles, attackers send Calendly meeting invites that redirect victims to typosquatted video conferencing domains impersonating Zoom and Microsoft Teams (such as us.zoom.06webin.us). Because the outreach originates from a known peer and relies on routine meeting workflows, initial skepticism is heavily minimized.

WebRTC Webcam Hijacking, AI Deepfakes, and Multi-OS Malware Delivery

Once a target lands on the phishing site, they are prompted to grant browser webcam permissions. Behind the scenes, the site silently streams the victim’s live video feed directly to an operator panel via WebRTC (mediasoup). To maintain cover, the attackers display a “waiting for other participants” screen while preparing an AI-driven video lure. They join the call displaying synthetic, ChatGPT-generated headshots superimposed over real body movements captured from past victims—creating a convincing, moving portrait of the trusted acquaintance.

While the video plays, the phishing kit fingerprints the browser to inventory installed cryptocurrency extension IDs (such as MetaMask). If a high-value victim is identified, the platform triggers a fake “SDK Update required” prompt—delivering tailored ClickFix payloads:

  • Windows Kill Chain: Executes a PowerShell loader that fetches a VBScript implant. It force-restarts Microsoft Defender after adding C:\Users to its exclusion list, checks for active Telegram Web session cookies across major browsers to hijack the account, and collects browser wallet metadata.

  • macOS Kill Chain: Runs a shell script disguised as a Teams/Zoom installer to steal system metadata and extract Google Chrome master keys stored within the iCloud Keychain, exfiltrating the data via a dedicated Telegram channel named “Aurora”.

Security researchers note that BlueNoroff specifically targets Zoom and Teams over browser-first platforms like Google Meet because users expect desktop app updates on heavyweight clients, making the prompt far more believable.

🛡️ Our Perspective: The Rise of Operationalized Trust Abuse

As threat analysts, we view this as a dangerous evolution in identity abuse. BlueNoroff is no longer just spoofing domains; they are operationalizing trust by fusing Telegram account takeovers with AI-driven deepfake impersonations. This self-propagating loop—where each compromised account provides the source material and distribution channel for the next attack—makes traditional verification methods obsolete. Organizations must assume that text and video communications can be fabricated and must implement rigorous, out-of-band verification protocols for high-value asset transfers.

Privacy Preference Center