New Global Scam Uses Fake Meeting Links to Run PowerShell Malware
ID: 2a4631ee-7023-5c8b-a950-a399cc71caf5
STIX ID: report--2a4631ee-7023-5c8b-a950-a399cc71caf5
Feed Name: TechRepublic Security
Threat Score
Arctic Wolf uncovered a BlueNoroff campaign targeting Web3 and crypto organizations that lures victims with deepfake impersonations and typosquatted meeting invites; when victims join, they are tricked into pasting a command that executes fileless PowerShell payloads which persist in memory, inject into Chromium browsers, and exfiltrate wallet keys and credentials—over 100 targets in 20+ countries were identified, primarily finance-related and high-profile individuals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
