North Korean Hackers Run Fake Zoom and Teams Sites to Rob Crypto Wallets

BlueNoroff's phishing kit screens visitors' crypto wallets before deciding who gets the malware, researchers say.

ThreatVectr Newsdesk· 4 min read
Full-frame overhead view of a cluttered developer's desk at night, glowing keyboard, open laptop showing abstract package manager output as coloured bars, small
Share

Key points

  • BlueNoroff, a hacking crew linked to North Korea, is running fake Zoom and Microsoft Teams login pages to trick finance and crypto staff into installing malware.
  • The phishing kit checks a visitor's browser for cryptocurrency wallet extensions before serving the payload, so only useful targets get infected.
  • Attackers are using real, hijacked industry contacts to make meeting invites look genuine.
  • The campaign is part of the wider ClickFix trend, where victims are told to paste a "fix" command into their own computer.
  • Targets are told to watch for Zoom or Teams links on lookalike domains and any prompt asking them to run a command.

A North Korean hacking group known as BlueNoroff is running a slick phishing operation that impersonates Zoom and Microsoft Teams, then quietly checks whether the victim owns cryptocurrency before infecting them.

The campaign was detailed by researchers this week and first reported by The Hacker News. It fits inside a broader wave of attacks known as ClickFix, where victims are walked through pasting a malicious command into their own machine under the guise of fixing a broken meeting.

How does the scam actually work?

Victims get a meeting invite from what looks like a real business contact. The link points to a typosquatted domain, meaning a web address that copies a real one but with a small spelling change, like swapping a letter or adding a word. The page mimics the Zoom or Teams join screen.

When the meeting "fails", the site tells the user to run a short command to repair audio or video. That command downloads BlueNoroff's malware.

Here is the twist. Before the site hands over any malicious code, it runs a check in the browser for cryptocurrency wallet extensions such as MetaMask or Phantom. If the visitor has no wallet, they get a harmless error. If they do, the attack proceeds.

That filtering keeps the operation quiet. Security researchers and curious analysts who stumble onto the page see nothing suspicious. Only real targets get burned.

Who is BlueNoroff and why crypto?

BlueNoroff is a sub-group of the Lazarus cluster, the umbrella name for hacking teams tied to North Korea's government. Its job, according to years of tracking by the FBI and the United Nations, is to steal money to fund the regime. Crypto theft has become its main line of work.

US authorities have attributed hundreds of millions of dollars in cryptocurrency theft to North Korean operators over the past two years, including the record Bybit intrusion in 2025.

What does the phishing kit look like on the inside?

Element Detail
Impersonated brands Zoom, Microsoft Teams
Delivery trick ClickFix-style "paste this command" prompt
Pre-infection check Browser scan for crypto wallet extensions
Lure source Hijacked real industry contacts and meeting threads
Attributed group BlueNoroff (Lazarus sub-cluster, DPRK)

The use of compromised, genuine business contacts is the part that makes this hard to spot. The invite does not come from a stranger. It comes from someone the victim has emailed before, on a topic they were already discussing.

What should staff and crypto holders do?

Treat every "click here to fix your meeting" instruction as hostile. Zoom and Teams do not ask you to open a terminal or run a PowerShell command to join a call. If a meeting link fails, close the tab and rejoin from the official app.

Check the domain before you click. Real Zoom links sit on zoom.us and real Teams links sit on teams.microsoft.com or teams.live.com. Anything with extra words, hyphens or unusual endings is suspect.

If you handle crypto for work, keep signing wallets on a separate device from the one you use for email and meetings. Cold storage is boring. It is also what saves you here.

Regulatory jurisdiction on the victim side will depend on where the stolen funds and personal data sit. In the US that pulls in the FBI and the SEC for any listed firm that loses material assets; in the UK the ICO would expect a breach notification if employee or customer data was taken alongside the crypto.

© 2026 Threat Vectr