logo

Fileless PowerShell Attack Linked To New BlueNoroff Cyber Campaign

ID: 16417272-0344-5f8c-be79-1d6aa91fffd3

STIX ID: report--16417272-0344-5f8c-be79-1d6aa91fffd3

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Varshini

...
...

Arctic Wolf attributes a global campaign to BlueNoroff targeting Web3 and cryptocurrency organizations: attackers use spear-phishing with typo-squatted meeting links and AI-generated deepfakes to prompt victims into copying a malicious fileless PowerShell command (a "ClickFix" clipboard attack) that loads an in-memory C2 implant; subsequent post-exploitation modules steal Telegram sessions, inject AES-encrypted shellcode into Chromium-based browsers to extract master keys and wallet credentials, capture screenshots, and exfiltrate data — over 100 individuals across 20 countries were targeted, many of whom are CEOs or founders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.