**Zoom and Microsoft Teams Phishing Campaigns on the Rise: How BlueNoroff is Exploiting Trust for Crypto Theft**
In a startling development in cybersecurity, threat actors linked to North Korea are executing sophisticated phishing campaigns that exploit the trust inherent in professional communication platforms. According to a recent report by JUMPSEC, the BlueNoroff threat group has operationalised a new attack chain that leverages typosquatted domains of Zoom and Microsoft Teams to steal cryptocurrency from high-value targets.
The campaign represents a significant evolution in social engineering, moving beyond simple credential theft to a comprehensive operation that profiles victims before delivering malware. By compromising trusted contacts within a target organisation or network, the attackers initiate a self-propagating chain of deception that ultimately leads to malware installation and cryptocurrency theft.
**The Mechanics of the Attack**
The attack begins with a lure, often delivered via a compromised Telegram account of a legitimate contact. This message contains a link to a fake Calendly page, which redirects the victim to a counterfeit Zoom or Microsoft Teams login page. The realism of these pages is enhanced by the use of AI-generated video; the victim sees a fake meeting with a familiar face, created using AI avatars and superimposed on authentic body movements captured from previous legitimate meetings.
Once the “victim” joins the fake meeting, the attackers gain full control of the session, displaying fake “audio not working” messages and fake SDK update prompts to manipulate the user. Concurrently, a fingerprinting script runs in the background, scanning the victim’s browser for cryptocurrency wallet extensions such as MetaMask. This allows the attackers to identify and specifically target high-value wallets, making the campaign highly selective and profitable.
**Technical Execution and Infrastructure**
The technical execution differs slightly between Windows and macOS targets. On Windows, the attack chain uses a PowerShell loader that executes a VBScript implant. This implant is designed to disable Microsoft Defender, locate Telegram session data, and identify cryptocurrency wallet extensions. On macOS, a fake installer for Teams or Zoom is delivered, which steals sensitive data, including Chrome master keys and system metadata, exfiltrating it via a Telegram channel.
The threat actors behind this operation have been named “John” (@alchemy_john_mac) by researchers. The infrastructure has been actively refined, with five distinct versions of the phishing kit identified between May and July 2026. Analysis of the Telegram bot token revealed it was hard-coded into the stealer binary, linking it directly to the operator.
**Why Zoom and Teams?**
JUMPSEC’s research highlights three main reasons for the focus on Zoom and Microsoft Teams:
1. **The Pretext:** The “SDK out of date” narrative is believable only on platforms with heavyweight desktop clients, which Zoom and Teams possess. Google Meet, being browser-first, does not fit this profile.
2. **Target Profile:** Zoom and Teams are the standard communication tools for cryptocurrency investors and venture capitalists, the primary financial targets of the BlueNoroff group. Google Meet lacks this professional association.
3. **Typosquatting Surface:** The sub-domain structure of Zoom and Teams makes it easier to create convincing typosquatted domains that deceive users more easily than `meet.google.com`.
**Conclusion**
The BlueNoroff campaign represents a dangerous convergence of social engineering, identity compromise, and financial motivation. By hijacking trusted relationships and using sophisticated AI to create believable impersonations, attackers are blurring the line between the digital and physical worlds. This evolution underscores a critical shift in cybersecurity: the most valuable asset is no longer just data, but the trust and relationships that exist between people. Organisations must now prioritise the security of their communication channels and the identity of their users as a core component of their defence strategy.
—
### FAQ
**Q1: What is the ClickFix-style campaign mentioned in the article?**
A1: ClickFix is a social engineering tactic where attackers lure victims into solving a fake problem (like a missing microphone or camera issue) on a fraudulent page. In this campaign, the pretext is an outdated Zoom or Teams SDK, tricking users into interacting with a malicious link that ultimately leads to malware deployment or theft.
**Q2: What is the difference between the Zoom and Teams lures?**
A2: The Microsoft Teams variant is considered more polished than the Zoom version. It includes more advanced features such as emoji reactions, the ability to block mobile and tablet users, and pre-delivery probes to check for cryptocurrency wallet extensions before the final malware payload is delivered.
**Q3: How can I identify a phishing link for a fake Zoom or Teams meeting?**
A3: Always verify the URL directly. Phishing links often use typosquatting (e.g., `us.zoom.06webin.us` instead of `zoom.us`). Be extremely cautious of unsolicited meeting links, especially those claiming there is a technical issue with your audio or video that requires you to download software or grant permissions.
**Q4: What can organisations do to defend against these attacks?**
A4: Organisations should treat communication channels like email and messaging apps as critical security perimeters. This includes enforcing strict link-scaning policies, implementing multi-factor authentication (MFA) on all accounts, and conducting regular security awareness training that focuses on the latest social engineering techniques.
**Q5: Why are cryptocurrency wallets specifically being targeted?**
A5: The attackers are financially motivated. By scanning for wallet extensions like MetaMask, they can identify high-net-worth individuals who are likely to hold significant cryptocurrency. This allows them to bypass low-value targets and focus on maximising their return on the attack effort.
—
### Conclusion
The evolution of the BlueNoroff threat actor’s tactics marks a significant step forward in cybercrime. This is no longer just about deploying ransomware; it is about intelligence gathering, identity theft, and the surgical theft of digital assets. By weaponising trust and leveraging AI, these attackers have created a blueprint for the next generation of phishing. For security professionals, the lesson is clear: defending the perimeter is no longer enough. The human element—the trust between colleagues—must be secured with the same rigour as our firewalls and encryption.



