logo

BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures

ID: 6e6116a5-7a19-5593-b640-3df4ac2234a5

STIX ID: report--6e6116a5-7a19-5593-b640-3df4ac2234a5

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-04-28

Date Updated: 2026-05-08

Author: Jai Vijayan

...
...

Arctic Wolf reports a sophisticated BlueNoroff campaign targeting cryptocurrency executives using typo-squatted meeting links and convincing fake Zoom/Teams lobbies (AI-generated avatars and stolen webcam footage) to trick victims into granting camera/microphone access and installing malicious payloads; the chain leads from calendar invite to full compromise in minutes and is used to harvest credentials, steal crypto wallets and Telegram sessions while generating deepfake content for future attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.