logo

New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures

ID: c1403fc8-bfa2-5ccf-a3ec-1b1be8cda2d8

STIX ID: report--c1403fc8-bfa2-5ccf-a3ec-1b1be8cda2d8

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Tushar Subhra Dutta

...
...

Arctic Wolf attributes a widespread, high-risk campaign to Lazarus/BlueNoroff targeting cryptocurrency and Web3 professionals: attackers use spear-phishing Calendly invites that swap meeting links for typo-squatted Zoom pages hosting a faux meeting UI that tricks victims into copying diagnostic commands; a clipboard-hijack inserts a hidden PowerShell payload which downloads an obfuscated fileless C2 implant (chromechip.log) that profiles systems, exfiltrates browser credentials, Telegram session data, and webcam footage, and feeds an AI-driven deepfake pipeline to improve future lures—resulting in multi-country impact, 66 days of persistence in one intrusion, and the theft of high-value assets and credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.