← Back to Feed
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
July 24, 2026 · The Hacker News · Severity: HIGH
The North Korean BlueNoroff threat actor operates an active phishing kit impersonating Zoom and Microsoft Teams to deliver malware. Using typosquatted domains and ClickFix-style social engineering, the group profiles victims' cryptocurrency wallets before malware delivery for selective targeting of high-value victims. The campaign uses compromised trusted contacts as initial access vectors, creating a self-propagating attack chain via Telegram. JUMPSEC describes it as an operator-driven victim acquisition platform.
Key Takeaways
- BlueNoroff uses typosquatted Zoom and Teams domains with ClickFix-style lures to deliver malware to crypto targets.
- The phishing kit profiles victims' cryptocurrency wallets before delivering malware for selective high-value targeting.
- JUMPSEC describes the operation as an operator-driven victim acquisition platform with repeatable victim pipeline.