Go to app

Threat Assessment for Wallet Holders

Published 7/26/2026, 5:19:01 AM

The BLUENOROFF Zoom phishing campaign (also known as GhostCall or Hidden Risk) is a critical and direct threat to cryptocurrency wallet holders. This state-sponsored operation, attributed to North Korean threat actors (APT38/TA444), is specifically engineered to infiltrate systems and drain digital assets from high-value targets in the blockchain industry [Source: https://arcticwolf.com/resources/blog/bluenoroff-zoom-phishing/].

Threat Assessment for Wallet Holders

The campaign is a precision-engineered "victim acquisition pipeline" that profiles targets based on their crypto activity.

MetricDetail
Primary Target Sector54% of targets are in Cryptocurrency/Blockchain Finance (Exchanges, DeFi, Wallets) [Source: https://arcticwolf.com/resources/blog/bluenoroff-zoom-phishing/].
Target Seniority76% of victims are C-suite executives, Founders, or senior leadership [Source: https://arcticwolf.com/resources/blog/bluenoroff-zoom-phishing/].
Wallet ProfilingThe malware scans 10+ browsers (Chrome, Brave, Edge) to identify specific wallet extension IDs, including MetaMask, Trust Wallet, and Coinbase Wallet [Source: https://thehackernews.com/2026/07/bluenoroff-phishing-kit-profiles-crypto.html].
PersistenceAttackers have maintained system access for over 66 days in documented cases to wait for high-value transactions [Source: https://arcticwolf.com/resources/blog/bluenoroff-zoom-phishing/].

Attack Mechanics: The "ClickFix" Method

The campaign uses a sophisticated social engineering cycle to bypass traditional security awareness:

  1. Initial Contact: Victims receive a Telegram or LinkedIn message from a "trusted" contact whose account has already been hijacked.
  2. The Lure: A Calendly invite for a professional meeting redirects the user to a typo-squatted domain (e.g., us05web-zoom[.]biz instead of zoom.us) [Source: https://huntress.com/blog/macos-malware-bluenoroff-zoom-phishing].
  3. The Deepfake: Users join a "Zoom" call featuring AI-generated deepfakes of known industry figures to establish legitimacy.
  4. The Payload: A fake error message claims the "Zoom SDK is out of date" and instructs the user to copy-paste a command into their terminal or PowerShell to "fix" it.
  5. Execution: This command installs a multi-stage backdoor (such as CryptoBot or RustBucket) that scans for private keys and can even replace MetaMask's background.js to intercept transactions [Source: https://thehackernews.com/2026/07/bluenoroff-phishing-kit-profiles-crypto.html].

Key Indicators of Compromise (IOCs)

If you have interacted with any of the following, your wallet security may be compromised:

  • Malicious Domains: uu03webzoom[.]us, support[.]us05web-zoom[.]biz, teams-live[.]org, zoom-client[.]com [Source: https://huntress.com/blog/macos-malware-bluenoroff-zoom-phishing].
  • Suspicious Files: zoom_sdk_support.scpt (macOS), chromechip.log (Windows), or unexpected LaunchDaemons in /Library/LaunchDaemons/.
  • Behavioral Red Flag: Any request to run terminal commands or scripts to "fix" a video conferencing issue is a 100% indicator of a malicious attack.

Conclusion

The BLUENOROFF campaign is a credible and highly dangerous threat to anyone holding crypto assets, particularly those active in professional Web3 circles. The use of deepfakes and "ClickFix" terminal commands makes it significantly more effective than standard phishing. Any "Zoom" or "Teams" invite requiring manual script execution should be treated as a confirmed security risk.