logo

Inside BlueNoroff’s “Self-Reinforcing” Deepfake Meeting Trap

ID: b8e322de-d9eb-5adb-a3d7-840c542eea6d

STIX ID: report--b8e322de-d9eb-5adb-a3d7-840c542eea6d

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

Arctic Wolf reveals a global BlueNoroff (Lazarus subgroup) campaign that lures cryptocurrency and Web3 executives into typo‑squatted fake Zoom/Teams meetings rendered by JavaScript, where deepfake participants (stolen webcam footage, AI stills, and composite videos) are used to prompt victims to run a fake “update” troubleshooting flow that deploys a PowerShell-based C2 implant; targeting patterns and activity hours align with DPRK state-sponsored operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.