North Korean threat actors are utilizing sophisticated phishing kits and compromised Telegram accounts to impersonate Zoom and Microsoft Teams, targeting cryptocurrency professionals with malware and session-stealing payloads.
Key Points
- The BlueNoroff group uses typosquatted domains and fake videoconferencing interfaces to trick victims into running malicious "ClickFix" commands.
- Attackers hijack trusted Telegram contacts to distribute Calendly links, creating a self-propagating attack chain that targets high-value individuals in the finance and crypto sectors.
- The phishing kit employs AI-generated video composites and browser fingerprinting to identify high-value cryptocurrency wallets before deploying Windows or macOS malware.
- Malware payloads are designed to disable Microsoft Defender, exfiltrate browser session cookies, and steal sensitive data from iCloud Keychains.
- JUMPSEC researchers identified five versions of the phishing kit developed between May and July 2026, confirming active refinement of the platform.