AUTO-UPDATED

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

North Korean threat actors are utilizing sophisticated phishing kits and compromised Telegram accounts to impersonate Zoom and Microsoft Teams, targeting cryptocurrency professionals with malware and session-stealing payloads.

Key Points

  • The BlueNoroff group uses typosquatted domains and fake videoconferencing interfaces to trick victims into running malicious "ClickFix" commands.
  • Attackers hijack trusted Telegram contacts to distribute Calendly links, creating a self-propagating attack chain that targets high-value individuals in the finance and crypto sectors.
  • The phishing kit employs AI-generated video composites and browser fingerprinting to identify high-value cryptocurrency wallets before deploying Windows or macOS malware.
  • Malware payloads are designed to disable Microsoft Defender, exfiltrate browser session cookies, and steal sensitive data from iCloud Keychains.
  • JUMPSEC researchers identified five versions of the phishing kit developed between May and July 2026, confirming active refinement of the platform.

Why it Matters

This campaign highlights a dangerous evolution in social engineering where attackers leverage existing professional relationships and AI-enhanced media to bypass traditional security skepticism. By targeting the individuals who control digital assets rather than just infrastructure, these threat actors demonstrate that personal communication channels have become a critical, high-risk attack surface for modern organizations.
Internet Published by info@thehackernews.com (The Hacker News)
Read original