Crypto Prices

BlueNoroff Exploits Fake Meetings to Target Crypto Users in Sophisticated Hacking Campaign

15 hours ago
3 mins read
4 views

North Korea’s BlueNoroff Hacking Collective

A North Korea-affiliated hacking collective known as BlueNoroff has been employing fraudulent Zoom and Microsoft Teams meetings as a tactic to identify cryptocurrency investors, ultimately facilitating the delivery of malicious software. Recent disclosures from the cybersecurity firm JUMPSEC reveal that they uncovered the source code of an active phishing toolkit after the exploitation of JavaScript maps on an exposed network by the hackers. This code featured deceptive Zoom and Teams frameworks alongside wallet-scanning functionalities, control mechanisms, and methods for distributing malware targeting both Windows and macOS platforms.

Modus Operandi

The modus operandi usually initiates when attackers use a compromised Telegram account that their target trusts, often belonging to someone within the cryptocurrency community. By infiltrating these accounts, hackers can dispatch enticing Calendly invitations that redirect victims to fake meeting sites. According to JUMPSEC, this process creates what they refer to as a “repeatable victim pipeline,” as one hacked Telegram account can facilitate multiple subsequent attacks.

Phishing Techniques

Once victims connect to the fraudulent meeting, a phishing page begins to scan their browser for Ethereum wallet connections using the EIP-6963 protocol along with older browser methods. Notably, it also screens for non-EVM wallets, encompassing tools from Solana, all while ensuring that the victim remains unaware of these scans. Insights gleaned from this probing are relayed to a control panel operated by the attackers, allowing them to pinpoint lucrative targets prior to advancing to the next stage of the attack.

Malware Delivery

For users on Windows systems, the malware collects extension identifiers across numerous browser types, including Chrome, Edge, Brave, Opera, Vivaldi, and Firefox. This intelligence allows attackers to correlate the identifiers with known wallet extensions like MetaMask, effectively performing what JUMPSEC describes as “wallet profiling before malware delivery.” This sophisticated approach stands in stark contrast to traditional phishing methods, as it allows the perpetrators to sift through wallet information before determining the level of intrusion required.

Victim Interaction

Victims are greeted by an authentic-looking meeting page which prompts them to provide their name and grant webcam access. After joining, they are shown a screen with a message indicating “waiting for other participants.” Attackers can then enter the session, outfitted with pre-recorded videos, and interact with victims by sending messages suggesting technical difficulties, as well as prompting a fake “Zoom SDK Update.”

Advanced Techniques

JUMPSEC discovered that the participant visuals displayed are not live feeds; instead, the hackers utilize AI-generated images combined with recorded motions from prior meetings to mimic a real contact’s appearance. The Teams impersonation appears even more refined, featuring emoji responses, customizable device settings, and enhanced wallet audits. The attack even includes a rudimentary Google Meet alternative within the code. The reliance on Zoom and Teams is strategic, as both applications operate on desktop clients—a factor that amplifies the urgency and plausibility of software updates.

Payloads and System Insights

For Windows systems, the fraudulent ClickFix command activates a small PowerShell loader that downloads a VBScript, establishes exclusions in Microsoft Defender, and reboots Defender to validate these alterations. This implant collects various system insights, audits browser wallet extensions, and specifies relevant Telegram Web files. Notably, it can receive additional payloads from hackers. However, JUMPSEC noted that they were not able to recover all final payloads used in the attack.

macOS Attack Vector

In contrast, the macOS attack vector involves the installation of fraudulent Zoom or Teams applications, while a stealer operates in the background, gathering system data and Chrome master keys from Apple’s Keychain. Information harvested is relayed via a Telegram bot, with the capacity for secondary payload downloads. Between April 22 and July 15, JUMPSEC traced multiple macOS variants indicating a dynamic adjustment of their toolkit during the campaign.

Victim Statistics

Previously, Arctic Wolf reported over 80 fraudulent domains mimicking Zoom and Teams, targeting more than 100 individuals whose credentials were exposed through the hackers’ infrastructure. Notably, a staggering 80% of the identified victims were entrenched in the cryptocurrency or blockchain finance sectors, with 45% being high-ranking executives.

Historical Context and Recommendations

Historically, North Korean hackers have leveraged hacked Telegram accounts, counterfeit meeting invitations, and phony software updates to stalk cryptocurrency executives. A related campaign on macOS was documented, where scammers urged victims to execute commands during sham video conferences. Previous reports linking the NimDoor malware also highlighted such impersonations as conduits for stealing browser credentials, wallet information, and Telegram data.

With this latest toolkit, attackers can exercise controlling influence over the rhythm and progression of fake meetings along with malware deployment. JUMPSEC advises that organizations remain vigilant when engaging with meeting links stemming from trusted contacts, as these accounts may already be compromised. Crypto teams are encouraged to verify unusual digital invitations through alternative channels, refrain from executing commands or updates during live calls, revoke compromised Telegram sessions, and isolate any device exposed to these potentially harmful scripts. Beyond password resets, additional scrutiny of PowerShell activity, Defender exclusions, Keychain access, and fresh Telegram logins is critical to harnessing protection against future risks.

Popular