Arctic Wolf researchers have uncovered a highly sophisticated cyber intrusion targeting a North American Web3 and cryptocurrency organization.
With high confidence, researchers attribute this ongoing global campaign to BlueNoroff, a financially motivated cybercrime subgroup of North Korea’s Lazarus Group.
The threat actors are using advanced social engineering, AI-generated deepfakes, and a unique fileless PowerShell attack to compromise high-value targets in the financial sector.
Deceptive Meetings and Deepfakes
The attack lifecycle begins with a carefully crafted social engineering approach. Threat actors impersonate reputable figures in the financial technology or legal sectors, reaching out to targets to schedule meetings.
They use spear-phishing techniques to deliver a manipulated Calendly calendar invitation that contains a typo-squatted Zoom or Microsoft Teams link. This malicious link is designed to look almost identical to a legitimate meeting URL.

Fileless Execution and Exploitation
As the fake meeting progresses, the victim realizes the audio is not working.
The malicious interface then displays a deceptive error message, claiming the victim’s video conferencing software development kit (SDK) is outdated and requires an immediate update. This triggers a “ClickFix” clipboard injection attack.
The victim is instructed to copy and paste what appears to be a harmless diagnostic command into the Windows Run dialog or a terminal. In reality, the victim is copying a malicious, fileless PowerShell script.

This initial PowerShell command downloads and executes an obfuscated secondary script from a command-and-control (C2) server.
The script establishes a persistent C2 implant in the system’s memory, allowing the attackers continuous access to the compromised machine. From there, BlueNoroff operators quickly deploy a series of post-exploitation modules.

The primary goal of these modules is to steal data and harvest credentials. The attackers deploy a script to steal Telegram Desktop sessions, allowing them to hijack the victim’s messaging account to approach new targets.
Shortly after, a sophisticated browser injection payload is launched. This payload injects AES-encrypted shellcode directly into running Chromium-based browsers, such as Chrome, Edge, and Brave.
The injected code bypasses browser security mechanisms to extract master encryption keys and decrypt stored credentials.
The stealers specifically target cryptocurrency wallet extensions, login data, and browser history.
In addition to credential theft, the malware captures high-quality screenshots of the victim’s desktop, either sending them via HTTP requests or exfiltrating them through a customized Telegram Bot API.
Arctic Wolf’s investigation identified over 100 individuals targeted by this campaign across 20 different countries. The heaviest concentration of victims is in the United States, followed by Singapore and the United Kingdom.
With nearly half of the targets holding CEO or founder titles, BlueNoroff’s operation highlights a precise, globally distributed effort to steal cryptocurrency through highly convincing, fileless attack chains.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.