A recent report has uncovered a phishing kit operated by North Korean threat actors, specifically targeting users of Zoom and Microsoft Teams. This kit is designed to impersonate these videoconferencing platforms in social engineering campaigns aimed at delivering malware.
Phishing Kit Overview
The cybersecurity firm JUMPSEC revealed that the group, known as BlueNoroff, has developed a systematic approach to victim acquisition. This involves leveraging compromised contacts, social engineering, and reconnaissance of cryptocurrency wallets before executing malware delivery. The report describes this operation as a self-sustaining attack chain that utilizes trusted contacts to propagate the attack via Telegram.
Mechanics of the Attack
The phishing campaign has been documented since early 2025, with the attackers hijacking legitimate Telegram accounts of individuals in the cryptocurrency sector. They initiate contact with high-ranking employees at major companies, sharing a Calendly link that appears to lead to a Zoom meeting. Instead, it directs victims to a fraudulent domain mimicking Zoom.
Upon accessing the phishing page, users are prompted to enter their names and grant webcam permissions. Once permissions are granted, the webcam feed is covertly transmitted to the attackers. Victims are then shown a fake Zoom meeting interface, creating an illusion of a legitimate call.
Technical Details of the Malware
The phishing kit operates differently on Windows and macOS systems. On Windows, it executes a PowerShell loader that downloads a VBScript, which disables Microsoft Defender and checks for active Telegram sessions. This allows the attackers to hijack session cookies and target other individuals. On macOS, the kit downloads a fake Teams or Zoom installer that extracts sensitive data, including Google Chrome master keys, and sends it to the attackers via a Telegram channel.
Ongoing Development and Implications
Recent analysis has shown that the phishing kit has undergone active development, with five distinct versions identified between May 31 and July 14, 2026. The focus on Zoom and Teams, rather than other platforms like Google Meet, is attributed to the perceived trust and familiarity associated with these applications among cryptocurrency users.
JUMPSEC emphasizes that the implications of this campaign extend beyond immediate threats, highlighting the importance of considering identity and communication channels in organizational security strategies.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.
Original source: thehackernews.com








