MEDIUMMalware
Global

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

·Source: The Hacker News

Updated:

Executive Summary

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. "BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet

Analysis

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. "BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet
Source Attribution

Originally published by The Hacker News on Jul 24, 2026.

Related Threats