BlueNoroff Hackers Use Fake Zoom Calls to Scan Crypto Wallets
A North Korean hacking group called BlueNoroff has been using fake Zoom and Microsoft Teams calls to scan crypto wallets before infecting them with malware. The group's operation targets individuals who hold private keys, and it can compromise a victim's wallet in under five minutes.
JUMPSEC, a UK security firm, released an analysis of the source code for BlueNoroff's operation, revealing that the hackers use JavaScript to scan a target's browser as soon as they land on the fake meeting page. The malware looks for Ethereum connections with the EIP-6963 standard and legacy browser techniques, and it also probes for non-EVM wallets like Solana tools.
The attackers then use a list of browser extension IDs to check against known wallet extensions like MetaMask, allowing them to identify which wallets are worth targeting. The malware can collect system information, search for wallet extensions in browsers, and even steal Chrome master keys from Apple's Keychain on macOS.