Threat Assessment for Wallet Holders
Published 7/26/2026, 5:19:01 AM
The BLUENOROFF Zoom phishing campaign (also known as GhostCall or Hidden Risk) is a critical and direct threat to cryptocurrency wallet holders. This state-sponsored operation, attributed to North Korean threat actors (APT38/TA444), is specifically engineered to infiltrate systems and drain digital assets from high-value targets in the blockchain industry [Source: https://arcticwolf.com/resources/blog/bluenoroff-zoom-phishing/].
Threat Assessment for Wallet Holders
The campaign is a precision-engineered "victim acquisition pipeline" that profiles targets based on their crypto activity.
| Metric | Detail |
|---|---|
| Primary Target Sector | 54% of targets are in Cryptocurrency/Blockchain Finance (Exchanges, DeFi, Wallets) [Source: https://arcticwolf.com/resources/blog/bluenoroff-zoom-phishing/]. |
| Target Seniority | 76% of victims are C-suite executives, Founders, or senior leadership [Source: https://arcticwolf.com/resources/blog/bluenoroff-zoom-phishing/]. |
| Wallet Profiling | The malware scans 10+ browsers (Chrome, Brave, Edge) to identify specific wallet extension IDs, including MetaMask, Trust Wallet, and Coinbase Wallet [Source: https://thehackernews.com/2026/07/bluenoroff-phishing-kit-profiles-crypto.html]. |
| Persistence | Attackers have maintained system access for over 66 days in documented cases to wait for high-value transactions [Source: https://arcticwolf.com/resources/blog/bluenoroff-zoom-phishing/]. |
Attack Mechanics: The "ClickFix" Method
The campaign uses a sophisticated social engineering cycle to bypass traditional security awareness:
- Initial Contact: Victims receive a Telegram or LinkedIn message from a "trusted" contact whose account has already been hijacked.
- The Lure: A Calendly invite for a professional meeting redirects the user to a typo-squatted domain (e.g.,
us05web-zoom[.]bizinstead ofzoom.us) [Source: https://huntress.com/blog/macos-malware-bluenoroff-zoom-phishing]. - The Deepfake: Users join a "Zoom" call featuring AI-generated deepfakes of known industry figures to establish legitimacy.
- The Payload: A fake error message claims the "Zoom SDK is out of date" and instructs the user to copy-paste a command into their terminal or PowerShell to "fix" it.
- Execution: This command installs a multi-stage backdoor (such as CryptoBot or RustBucket) that scans for private keys and can even replace MetaMask's
background.jsto intercept transactions [Source: https://thehackernews.com/2026/07/bluenoroff-phishing-kit-profiles-crypto.html].
Key Indicators of Compromise (IOCs)
If you have interacted with any of the following, your wallet security may be compromised:
- Malicious Domains:
uu03webzoom[.]us,support[.]us05web-zoom[.]biz,teams-live[.]org,zoom-client[.]com[Source: https://huntress.com/blog/macos-malware-bluenoroff-zoom-phishing]. - Suspicious Files:
zoom_sdk_support.scpt(macOS),chromechip.log(Windows), or unexpected LaunchDaemons in/Library/LaunchDaemons/. - Behavioral Red Flag: Any request to run terminal commands or scripts to "fix" a video conferencing issue is a 100% indicator of a malicious attack.
Conclusion
The BLUENOROFF campaign is a credible and highly dangerous threat to anyone holding crypto assets, particularly those active in professional Web3 circles. The use of deepfakes and "ClickFix" terminal commands makes it significantly more effective than standard phishing. Any "Zoom" or "Teams" invite requiring manual script execution should be treated as a confirmed security risk.