thehackernews.com web signal

BlueNoroff builds Zoom phishing kit with ChatGPT-made faces

TL;DR

  • JUMPSEC identified five distinct BlueNoroff phishing kit versions between May 31 and July 14, 2026, indicating active development.
  • Fake meetings play pre-edited video with headshots generated by OpenAI ChatGPT, superimposed over body movements captured during previous meetings.
  • The kit fingerprints browser wallet extensions like MetaMask before dropping Windows or macOS malware, selectively targeting crypto holders.

A North Korean crew is running fake Zoom and Teams meetings polished enough to fool crypto executives, and the twist is where the faces come from. The Hacker News, reporting a JUMPSEC investigation, says BlueNoroff has built a phishing kit that plays victims a pre-edited video with AI-generated headshots created using OpenAI ChatGPT, superimposed over authentic body movements captured during previous meetings. Each successful compromise, JUMPSEC notes, feeds source material into the composites used against the next target. That is a self-refilling deepfake library, not a one-shot lure.

The setup around it is careful. Compromised Telegram accounts belonging to real crypto industry contacts send Calendly invites to high-ranking employees. The victim lands on a typosquatted domain, gets a prompt saying the Zoom or Teams SDK is out of date, grants webcam permission, and while the fake call plays, the kit inventories installed cryptocurrency wallet extensions across Chrome, Edge, Brave, Firefox, Opera and Vivaldi, matching IDs against known wallets like MetaMask. Sean Moran, JUMPSEC's head of threat research, told the outlet the pretext only lands on platforms that victims believe have a heavyweight desktop client, which is why Google Meet is not the target.

Only high-value browsers get malware. On Windows a PowerShell loader disables Microsoft Defender and a VBScript implant steals Telegram session cookies. On macOS a fake installer's stealer extracts Chrome master keys from iCloud Keychain and exfiltrates via a Telegram channel called Aurora. JUMPSEC found five distinct versions of the kit between May 31 and July 14, 2026, which reads as active tuning rather than a single campaign.

The honest caveat is what the reporting does not pin down: which ChatGPT surface was abused, whether any moderation check fired, how many victims lost funds, or the total value drained. What is clear is that a live-looking face on a Zoom call is no longer evidence anyone is really there, and any organisation whose transfer or deal-approval flow leans on 'I saw them on the call' has a control gap to close before the next kit version ships.