logo

New Global Scam Uses Fake Meeting Links to Run PowerShell Malware

ID: 2a4631ee-7023-5c8b-a950-a399cc71caf5

STIX ID: report--2a4631ee-7023-5c8b-a950-a399cc71caf5

Feed Name: TechRepublic Security

Threat Score
85/100

Date Published: 2026-04-30

Date Updated: 2026-05-01

Author: Joseph Ofonagoro

...
...

Arctic Wolf uncovered a BlueNoroff campaign targeting Web3 and crypto organizations that lures victims with deepfake impersonations and typosquatted meeting invites; when victims join, they are tricked into pasting a command that executes fileless PowerShell payloads which persist in memory, inject into Chromium browsers, and exfiltrate wallet keys and credentials—over 100 targets in 20+ countries were identified, primarily finance-related and high-profile individuals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.