Wallet Profiling TTPs (Tactics, Techniques, and
Published 7/26/2026, 1:02:27 PM
BlueNoroff, a sophisticated subgroup of the North Korean state-sponsored Lazarus Group, has transitioned from broad phishing to highly surgical wallet profiling. This tactic allows them to identify and categorize high-value crypto holders before deploying malware, ensuring their resources are focused exclusively on targets with significant liquidity.
In 2025, North Korean-linked groups were responsible for an estimated $2.02 billion in stolen cryptocurrency, including a record $1.5 billion theft from Bybit in February 2025 [Source: https://www.chainalysis.com/blog/2025-crypto-crime-report-preview-north-korea-theft/].
Wallet Profiling TTPs (Tactics, Techniques, and Procedures)
BlueNoroff's profiling is designed to inventory a victim's digital assets to determine if the target is "worth" the operational risk.
- Browser Fingerprinting: The group uses fake meeting pages (e.g., typosquatted domains like
zoom-class.com) that execute scripts to inventory installed browser extensions. They specifically target 23+ wallet extensions, including MetaMask, Phantom, Rabby, Keplr, OKX, and Ledger-compatible wallets [Source: https://www.sentinelone.com/labs/bluenoroff-evades-detection-with-new-macos-malware-targeting-crypto-firms/]. - Extension Tampering: A primary technique involves replacing the legitimate
background.jsfile of a user's MetaMask extension with a trojanized version. This modified code monitors for large transactions and notifies the attacker's Command & Control (C2) server in real-time [Source: https://securelist.com/bluenoroff-methods-of-bypassing-motw/108383/]. - Social Engineering Pipeline: Attackers often pose as recruiters or investors on LinkedIn, eventually moving the conversation to Telegram. They send Calendly links that lead to fake meeting interfaces where the profiling occurs under the guise of "joining a call" [Source: https://www.fbi.gov/news/press-releases/fbi-warns-of-north-korean-cyber-actors-targeting-cryptocurrency-industry].
Concrete Risks to High-Value Holders
| Risk Category | Technical Detail | Impact |
|---|---|---|
| Selective Targeting | Profiling identifies wallet value before malware delivery. | 100% of attacker effort is concentrated on high-net-worth individuals. |
| Transaction Manipulation | Malware modifies the recipient address and maximizes the amount during signing. | A single "legitimate" transaction can drain an entire wallet balance. |
| Hardware Wallet Bypass | Attackers intercept the signing process at the browser level. | Users may see a small amount on their UI, but the hardware wallet is tricked into signing a "drain all" command. |
| AI-Enhanced Deception | Use of deepfake video and AI-generated avatars in fake meetings. | High-value holders are tricked into running "fix" scripts by what appears to be a known industry executive. |
Vulnerability of High-Value Holders vs. Average Users
High-value holders are uniquely vulnerable due to their public professional profiles. BlueNoroff specifically targets C-suite executives, senior developers, and OTC traders whose roles are listed on LinkedIn or X (Twitter). While an average user might be ignored after initial profiling, a high-value holder triggers a "manual" phase of the attack where BlueNoroff operators use custom-tailored malware to bypass specific security configurations [Source: https://www.fbi.gov/news/press-releases/fbi-warns-of-north-korean-cyber-actors-targeting-cryptocurrency-industry].
Recent Campaign Evolution (2025-2026)
- ClickFix Attacks: A dominant 2026 trend where victims are prompted to run a "fix" command (clipboard injection) to resolve fake audio/video issues in a meeting, which immediately installs an infostealer [Source: https://www.sentinelone.com/labs/bluenoroff-evades-detection-with-new-macos-malware-targeting-crypto-firms/].
- Infrastructure: The group frequently uses the Telegram Bot API for data exfiltration, often sending stolen credentials and wallet data to an operator identified as "John" (@alchemy_john_mac) [Source: https://securelist.com/bluenoroff-methods-of-bypassing-motw/108383/].
Conclusion: BlueNoroff's profiling poses a severe risk by removing the "security through obscurity" that many high-value holders rely on. Once profiled, the risk shifts from generic phishing to a persistent, state-sponsored effort to manipulate the victim's specific wallet environment. Evidence for physical threats resulting directly from this profiling remains thin, but the technical risk of total asset loss is high.