Skip to content
BlueNoroff builds Zoom phishing kit with ChatGPT-made faces

BlueNoroff builds Zoom phishing kit with ChatGPT-made faces

Aiweekly.Co July 25, 2026

A North Korean crew is running fake Zoom and Teams meetings polished enough to fool crypto executives, and the twist is where the faces come from. The Hacker News , reporting a JUMPSEC investigation, says BlueNoroff has built a phishing kit that plays victims a pre-edited video with AI-generated headshots created using OpenAI ChatGPT, superimposed over authentic body movements captured during meetings. Each successful compromise, JUMPSEC notes, feeds source material into the composites used against the target. That is a self-refilling deepfake library, not a one-shot lure.

The setup around it is careful. Compromised Telegram accounts belonging to real crypto industry contacts send Calendly invites to high-ranking employees. The victim lands on a typosquatted domain, gets a prompt saying the Zoom or Teams SDK is out of date, grants webcam permission, and while the fake call plays, the kit inventories installed cryptocurrency wallet extensions across Chrome, Edge, Brave, Firefox, Opera and Vivaldi, matching IDs against known wallets like MetaMask. Sean Moran, JUMPSEC's head of threat research, told the outlet the pretext only lands on platforms that victims believe have a heavyweight desktop client, which is why Google Meet is not the target.

Only high-value browsers get malware. On Windows a PowerShell loader disables Microsoft Defender and a VBScript implant steals Telegram session cookies. On macOS a fake installer's stealer extracts Chrome master keys from iCloud Keychain and exfiltrates via a Telegram channel called Aurora. JUMPSEC found five distinct versions of the kit between May 31 and July 14, 2026, which reads as active tuning rather than a single campaign.

The honest caveat is what the reporting does not pin down: which ChatGPT surface was abused, whether any moderation check fired, how many victims lost funds, or the total value drained. What is clear is that a live-looking face on a Zoom call is no longer evidence anyone is really there, and any organisation whose transfer or deal-approval flow leans on 'I saw them on the call' has a control gap to close before the kit version ships.

Originally reported by thehackernews.com

Original headline: North Korea's BlueNoroff Uses OpenAI's GPT-4o to Generate Fake Zoom Meeting Participants in Phishing Kit