Go to app

Wallet Risks and Data Theft Mechanisms

Published 7/26/2026, 5:18:28 AM

The BlueNoroff (also known as TA444 or Sapphire Sleet) fake Zoom phishing kit is a sophisticated attack vector attributed to North Korean state-sponsored actors targeting the Web3 and cryptocurrency sectors. As of July 2026, the kit poses severe risks to wallet security by combining AI-generated deepfakes with "ClickFix" social engineering to achieve full system compromise and asset exfiltration in under five minutes [Source: https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/].

Wallet Risks and Data Theft Mechanisms

The kit is specifically designed to profile, compromise, and drain high-value cryptocurrency wallets. It targets over 20 browser-based wallet extensions, including MetaMask, Phantom, Trust Wallet, and Coinbase Wallet [Source: https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html].

Risk CategoryAttack MechanicImpact on Wallet Security
Pre-Infection ProfilingScans for 20+ wallet extensions across Chrome, Edge, Brave, and Firefox before deploying malware.Allows attackers to prioritize high-value targets and tailor payloads [Source: https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/].
Credential ExfiltrationExtracts Google Chrome master keys (macOS Keychain) and decrypts "Login Data" databases (Windows).Compromises saved passwords for exchanges and potentially stored seed phrases [Source: https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/].
Session HijackingSteals Telegram tdata folders and session keys.Grants access to 2FA codes sent via Telegram and private communications regarding wallet management [Source: https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/].
Clipboard MonitoringMonitors the system clipboard for wallet address patterns or private keys.Enables "address poisoning" or direct theft of copied seed phrases and private keys [Source: https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/].
Keylogging/Screen CaptureCaptures real-time keystrokes and screenshots during wallet interactions.Exfiltrates 2FA codes, wallet balances, and transaction details as they are entered [Source: https://www.huntress.com/blog/inside-bluenoroff-web3-intrusion-analysis].

The "Fake Meeting" Attack Chain

The attack typically begins with a compromised industry contact sending a Calendly link that redirects to a typo-squatted Zoom domain (e.g., us05web-zoom[.]biz) [Source: https://www.decryptiondigest.com/blog/bluenoroff-deepfake-zoom-crypto-clickfix].

  1. AI-Generated Deepfakes: Victims enter a fake lobby featuring AI-generated headshots superimposed on real body movements to simulate a legitimate meeting [Source: https://aiweekly.co/alerts/bluenoroff-builds-zoom-phishing-kit-with-chatgpt-made-faces].
  2. ClickFix Social Engineering: A fake "Zoom SDK Update" or "Mic Error" prompt appears, instructing the user to run a PowerShell command (Windows) or AppleScript (macOS).
  3. Fileless Execution: The command executes malware directly in memory, bypassing many traditional antivirus solutions to begin exfiltrating wallet data to a Command & Control (C2) server or a dedicated Telegram channel [Source: https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/].

Target Profile and Scale

Research indicates that the campaign is highly targeted toward senior leadership within the crypto space.

Note on Unresolved Claims: While the kit facilitates full wallet compromise via credential and session theft, current research data does not explicitly detail specific mechanisms for ERC-20 token approval harvesting, NFT-specific theft scripts, or bridge-to-wormhole exploits, though these are common outcomes of the full system access the kit provides.

Critical Indicators of Compromise (IOCs)

The primary risk is that the kit bypasses traditional security awareness by using trusted contacts and AI-generated visuals. Users should be aware that legitimate Zoom software never requires running terminal or PowerShell commands to resolve connection issues.