BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
North Korean-linked BlueNoroff operators are using typosquatted Zoom and Microsoft Teams domains, stolen Telegram accounts, and fake videoconferencing lures to deliver malware through a repeatable social-engineering pipeline. The phishing kit fingerprints victims’ browsers for cryptocurrency wallets, steals sessions, and uses AI-generated faces and edited video to make fake meetings look convincing. #BlueNoroff #Zoom #MicrosoftTeams #Telegram #Calendly #MetaMask

Keypoints

  • BlueNoroff uses compromised trusted contacts to seed phishing messages.
  • Fake Zoom and Microsoft Teams pages are used to impersonate meeting flows.
  • The kit checks victim browsers for cryptocurrency wallet extensions.
  • Telegram sessions can be stolen and reused to spread the campaign further.
  • Windows and macOS payloads deliver loaders, stealers, and defense evasion steps.

Read More: https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html