logo

North Korean Hackers Target Crypto Firms with ClickFix and AI-Made Zoom Lures

ID: 969873c7-7d86-56ae-8906-f309b49f2af5

STIX ID: report--969873c7-7d86-56ae-8906-f309b49f2af5

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

...
...

Arctic Wolf Labs attributes a sophisticated, BlueNoroff-linked spear-phishing campaign to Lazarus operatives who targeted more than 100 crypto and related firms across 20+ countries using typosquatted Zoom/Teams links, fake Calendly invites, clipboard/browser injection aimed at wallet extensions, a deepfake pipeline from exfiltrated webcam feeds, PowerShell C2 implants, AES-encrypted payloads and Telegram-based exfiltration; the campaign enabled rapid full-system compromise and prolonged access for credential and asset theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.