BlueNoroff Is Running a Fake Zoom Studio — and It's Watching Your Wallet First
North Korea's BlueNoroff hacking group has built what cybersecurity firm JUMPSEC calls a full victim acquisition platform, according to The Hacker News. It's not just a phishing page. It's a pipeline.
The attack begins when a target receives a Calendly invite from someone they already know and trust — because that contact's Telegram account has already been hijacked. The link leads to a convincing fake Zoom page that asks for camera permissions. Grant them, and your webcam feed goes straight to the attackers.
Here's the twist: before any malware is deployed, the kit quietly scans your browser for installed cryptocurrency wallets. Only high-value targets get the full treatment. Everyone else is catalogued for later.
When the fake meeting begins, the victim sees a pre-recorded AI-generated video of a familiar face — composited using ChatGPT-generated headshots over real body footage captured from previous victims. The "your mic isn't working" message is fake. The Zoom SDK update prompt it leads to is the malware delivery step.
Every compromised Telegram account feeds the next attack. One victim becomes the lure for their own contacts.
The campaign targets Windows and macOS users in the cryptocurrency industry. If you receive an unexpected meeting invite, even from a known contact, verify it through a separate channel before clicking anything.
Sources

