logo

BlueNoroff Targets Cryptocurrency Executives with AI-Enhanced Fake Zoom Attacks

ID: e252d51d-eb4c-5414-9c50-b1dddbd7e9e8

STIX ID: report--e252d51d-eb4c-5414-9c50-b1dddbd7e9e8

Feed Name: ThreatCluster

Threat Score
76/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

...
...

**Executive summary:** North Korea-linked BlueNoroff is conducting a sophisticated campaign against cryptocurrency executives using Calendly lures to route victims to fake Zoom calls where AI-generated avatars and stolen video are used to capture live webcam feeds and deploy fileless PowerShell malware; the campaign has compromised over 100 individuals across 20+ countries since January 2026 and maintained access for up to 66 days.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.