North Korean-linked BlueNoroff operators are using typosquatted Zoom and Microsoft Teams domains, stolen Telegram accounts, and fake videoconferencing lures to deliver malware through a repeatable social-engineering pipeline. The phishing kit fingerprints victims’ browsers for cryptocurrency wallets, steals sessions, and uses AI-generated faces and edited video to make fake meetings look convincing. #BlueNoroff #Zoom #MicrosoftTeams #Telegram #Calendly #MetaMask
Keypoints
- BlueNoroff uses compromised trusted contacts to seed phishing messages.
- Fake Zoom and Microsoft Teams pages are used to impersonate meeting flows.
- The kit checks victim browsers for cryptocurrency wallet extensions.
- Telegram sessions can be stolen and reused to spread the campaign further.
- Windows and macOS payloads deliver loaders, stealers, and defense evasion steps.
Read More: https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html