Wallet Risks and Data Theft Mechanisms
Published 7/26/2026, 5:18:28 AM
The BlueNoroff (also known as TA444 or Sapphire Sleet) fake Zoom phishing kit is a sophisticated attack vector attributed to North Korean state-sponsored actors targeting the Web3 and cryptocurrency sectors. As of July 2026, the kit poses severe risks to wallet security by combining AI-generated deepfakes with "ClickFix" social engineering to achieve full system compromise and asset exfiltration in under five minutes [Source: https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/].
Wallet Risks and Data Theft Mechanisms
The kit is specifically designed to profile, compromise, and drain high-value cryptocurrency wallets. It targets over 20 browser-based wallet extensions, including MetaMask, Phantom, Trust Wallet, and Coinbase Wallet [Source: https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html].
| Risk Category | Attack Mechanic | Impact on Wallet Security |
|---|---|---|
| Pre-Infection Profiling | Scans for 20+ wallet extensions across Chrome, Edge, Brave, and Firefox before deploying malware. | Allows attackers to prioritize high-value targets and tailor payloads [Source: https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/]. |
| Credential Exfiltration | Extracts Google Chrome master keys (macOS Keychain) and decrypts "Login Data" databases (Windows). | Compromises saved passwords for exchanges and potentially stored seed phrases [Source: https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/]. |
| Session Hijacking | Steals Telegram tdata folders and session keys. | Grants access to 2FA codes sent via Telegram and private communications regarding wallet management [Source: https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/]. |
| Clipboard Monitoring | Monitors the system clipboard for wallet address patterns or private keys. | Enables "address poisoning" or direct theft of copied seed phrases and private keys [Source: https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/]. |
| Keylogging/Screen Capture | Captures real-time keystrokes and screenshots during wallet interactions. | Exfiltrates 2FA codes, wallet balances, and transaction details as they are entered [Source: https://www.huntress.com/blog/inside-bluenoroff-web3-intrusion-analysis]. |
The "Fake Meeting" Attack Chain
The attack typically begins with a compromised industry contact sending a Calendly link that redirects to a typo-squatted Zoom domain (e.g., us05web-zoom[.]biz) [Source: https://www.decryptiondigest.com/blog/bluenoroff-deepfake-zoom-crypto-clickfix].
- AI-Generated Deepfakes: Victims enter a fake lobby featuring AI-generated headshots superimposed on real body movements to simulate a legitimate meeting [Source: https://aiweekly.co/alerts/bluenoroff-builds-zoom-phishing-kit-with-chatgpt-made-faces].
- ClickFix Social Engineering: A fake "Zoom SDK Update" or "Mic Error" prompt appears, instructing the user to run a PowerShell command (Windows) or AppleScript (macOS).
- Fileless Execution: The command executes malware directly in memory, bypassing many traditional antivirus solutions to begin exfiltrating wallet data to a Command & Control (C2) server or a dedicated Telegram channel [Source: https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/].
Target Profile and Scale
Research indicates that the campaign is highly targeted toward senior leadership within the crypto space.
- Target Demographics: 76% of targets are in senior leadership roles; 45% are C-suite executives or founders [Source: https://www.huntress.com/blog/inside-bluenoroff-web3-intrusion-analysis].
- Geographic Reach: Over 100 victims identified across 20+ countries as of July 2026 [Source: https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/].
Note on Unresolved Claims: While the kit facilitates full wallet compromise via credential and session theft, current research data does not explicitly detail specific mechanisms for ERC-20 token approval harvesting, NFT-specific theft scripts, or bridge-to-wormhole exploits, though these are common outcomes of the full system access the kit provides.
Critical Indicators of Compromise (IOCs)
- Suspicious Domains:
us05web-zoom[.]biz,uu03webzoom[.]us,safeupload[.]online,metamask[.]awaitingfor[.]site. - Local Artifacts: Presence of
chromechip.login the%TEMP%directory or LNK files in the Windows Startup folder namedChrome Update[Source: https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/].
The primary risk is that the kit bypasses traditional security awareness by using trusted contacts and AI-generated visuals. Users should be aware that legitimate Zoom software never requires running terminal or PowerShell commands to resolve connection issues.