BlueNoroff’s Phishing Kit Targets Crypto Wallets via Zoom Impersonation

A new phishing kit linked to North Korean threat actors is exploiting Zoom and Microsoft Teams to target cryptocurrency users, utilizing social engineering tactics to deliver malware.

A recent report has uncovered a phishing kit operated by North Korean threat actors, specifically targeting users of Zoom and Microsoft Teams. This kit is designed to impersonate these videoconferencing platforms in social engineering campaigns aimed at delivering malware.

Phishing Kit Overview

The cybersecurity firm JUMPSEC revealed that the group, known as BlueNoroff, has developed a systematic approach to victim acquisition. This involves leveraging compromised contacts, social engineering, and reconnaissance of cryptocurrency wallets before executing malware delivery. The report describes this operation as a self-sustaining attack chain that utilizes trusted contacts to propagate the attack via Telegram.

Mechanics of the Attack

The phishing campaign has been documented since early 2025, with the attackers hijacking legitimate Telegram accounts of individuals in the cryptocurrency sector. They initiate contact with high-ranking employees at major companies, sharing a Calendly link that appears to lead to a Zoom meeting. Instead, it directs victims to a fraudulent domain mimicking Zoom.

Upon accessing the phishing page, users are prompted to enter their names and grant webcam permissions. Once permissions are granted, the webcam feed is covertly transmitted to the attackers. Victims are then shown a fake Zoom meeting interface, creating an illusion of a legitimate call.

Technical Details of the Malware

The phishing kit operates differently on Windows and macOS systems. On Windows, it executes a PowerShell loader that downloads a VBScript, which disables Microsoft Defender and checks for active Telegram sessions. This allows the attackers to hijack session cookies and target other individuals. On macOS, the kit downloads a fake Teams or Zoom installer that extracts sensitive data, including Google Chrome master keys, and sends it to the attackers via a Telegram channel.

Ongoing Development and Implications

Recent analysis has shown that the phishing kit has undergone active development, with five distinct versions identified between May 31 and July 14, 2026. The focus on Zoom and Teams, rather than other platforms like Google Meet, is attributed to the perceived trust and familiarity associated with these applications among cryptocurrency users.

JUMPSEC emphasizes that the implications of this campaign extend beyond immediate threats, highlighting the importance of considering identity and communication channels in organizational security strategies.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Original source: thehackernews.com

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 399

Newsletter Updates

Enter your email address below and subscribe to our newsletter