New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures
ID: c1403fc8-bfa2-5ccf-a3ec-1b1be8cda2d8
STIX ID: report--c1403fc8-bfa2-5ccf-a3ec-1b1be8cda2d8
Feed Name: cybersecurityNews.com
Arctic Wolf attributes a widespread, high-risk campaign to Lazarus/BlueNoroff targeting cryptocurrency and Web3 professionals: attackers use spear-phishing Calendly invites that swap meeting links for typo-squatted Zoom pages hosting a faux meeting UI that tricks victims into copying diagnostic commands; a clipboard-hijack inserts a hidden PowerShell payload which downloads an obfuscated fileless C2 implant (chromechip.log) that profiles systems, exfiltrates browser credentials, Telegram session data, and webcam footage, and feeds an AI-driven deepfake pipeline to improve future lures—resulting in multi-country impact, 66 days of persistence in one intrusion, and the theft of high-value assets and credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
