BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
ID: 6ea7d5e4-03a1-5fa7-8249-dd63297cd729
STIX ID: report--6ea7d5e4-03a1-5fa7-8249-dd63297cd729
Feed Name: The Hacker News
JUMPSEC reports that North Korea-linked BlueNoroff operates a ClickFix phishing kit using typosquatted Zoom/Teams pages, compromised Telegram contacts, and AI-generated fake meeting video to socially engineer high-value crypto and corporate targets; the campaigns deploy cross-platform stealer/malware (Windows PowerShell/VBScript loader and macOS stealer), harvest browser wallet extensions and Telegram sessions, exfiltrate data via Telegram, and show active development and operator activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
