← Back to Feed

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

July 24, 2026 · The Hacker News · Severity: HIGH

The North Korean BlueNoroff threat actor operates an active phishing kit impersonating Zoom and Microsoft Teams to deliver malware. Using typosquatted domains and ClickFix-style social engineering, the group profiles victims' cryptocurrency wallets before malware delivery for selective targeting of high-value victims. The campaign uses compromised trusted contacts as initial access vectors, creating a self-propagating attack chain via Telegram. JUMPSEC describes it as an operator-driven victim acquisition platform.

Key Takeaways

  • BlueNoroff uses typosquatted Zoom and Teams domains with ClickFix-style lures to deliver malware to crypto targets.
  • The phishing kit profiles victims' cryptocurrency wallets before delivering malware for selective high-value targeting.
  • JUMPSEC describes the operation as an operator-driven victim acquisition platform with repeatable victim pipeline.
☕ Buy a Coffee