Go to app

Wallet Profiling TTPs (Tactics, Techniques, and

Published 7/26/2026, 1:02:27 PM

BlueNoroff, a sophisticated subgroup of the North Korean state-sponsored Lazarus Group, has transitioned from broad phishing to highly surgical wallet profiling. This tactic allows them to identify and categorize high-value crypto holders before deploying malware, ensuring their resources are focused exclusively on targets with significant liquidity.

In 2025, North Korean-linked groups were responsible for an estimated $2.02 billion in stolen cryptocurrency, including a record $1.5 billion theft from Bybit in February 2025 [Source: https://www.chainalysis.com/blog/2025-crypto-crime-report-preview-north-korea-theft/].

Wallet Profiling TTPs (Tactics, Techniques, and Procedures)

BlueNoroff's profiling is designed to inventory a victim's digital assets to determine if the target is "worth" the operational risk.

Concrete Risks to High-Value Holders

Risk CategoryTechnical DetailImpact
Selective TargetingProfiling identifies wallet value before malware delivery.100% of attacker effort is concentrated on high-net-worth individuals.
Transaction ManipulationMalware modifies the recipient address and maximizes the amount during signing.A single "legitimate" transaction can drain an entire wallet balance.
Hardware Wallet BypassAttackers intercept the signing process at the browser level.Users may see a small amount on their UI, but the hardware wallet is tricked into signing a "drain all" command.
AI-Enhanced DeceptionUse of deepfake video and AI-generated avatars in fake meetings.High-value holders are tricked into running "fix" scripts by what appears to be a known industry executive.

Vulnerability of High-Value Holders vs. Average Users

High-value holders are uniquely vulnerable due to their public professional profiles. BlueNoroff specifically targets C-suite executives, senior developers, and OTC traders whose roles are listed on LinkedIn or X (Twitter). While an average user might be ignored after initial profiling, a high-value holder triggers a "manual" phase of the attack where BlueNoroff operators use custom-tailored malware to bypass specific security configurations [Source: https://www.fbi.gov/news/press-releases/fbi-warns-of-north-korean-cyber-actors-targeting-cryptocurrency-industry].

Recent Campaign Evolution (2025-2026)

Conclusion: BlueNoroff's profiling poses a severe risk by removing the "security through obscurity" that many high-value holders rely on. Once profiled, the risk shifts from generic phishing to a persistent, state-sponsored effort to manipulate the victim's specific wallet environment. Evidence for physical threats resulting directly from this profiling remains thin, but the technical risk of total asset loss is high.