BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets
North Korea's BlueNoroff operates a phishing kit impersonating Zoom and Teams to profile crypto wallets before malware delivery. Here's what to do about it.
BlueNoroff, the North Korean threat group behind months of ClickFix-style campaigns targeting the crypto sector, is running an active phishing kit that impersonates Zoom and Microsoft Teams — and it profiles victims’ wallets before deciding whether to deliver the payload.
That detail comes from The Hacker News, July 24, 2026, which detailed how the group has operationalized what researchers are calling “trust abuse”: using compromised industry contacts to deliver convincing meeting invitations, then layering wallet-profiling logic into the kit to triage high-value targets before full malware deployment.
What’s confirmed
The campaign uses typosquatted domains impersonating Zoom and Microsoft Teams. Victims reach those domains through what appear to be legitimate meeting invites — made credible because they often originate from compromised contacts in the crypto industry, not cold outreach from strangers.
The wallet-profiling step is the operational detail worth noting. BlueNoroff isn’t broadcasting the same payload indiscriminately: the kit evaluates whether a target’s holdings justify the cost of full malware delivery. That’s a triage layer most commodity phishing kits skip.
BlueNoroff is part of the Lazarus Group constellation, attributed by the U.S. government to North Korea’s Reconnaissance General Bureau. Consistent focus on crypto theft. This kit is infrastructure, not a one-off campaign.
What to do
For anyone in crypto, fintech, or digital asset management:
- Verify meeting invites out-of-band. Any unexpected Zoom or Teams link — even from a known contact — warrants a quick confirmation through a separate channel: phone call, Signal, or reply to a known email thread. The compromised-contact vector is specifically designed to defeat “I don’t click links from strangers.”
- Check the domain before the meeting loads. Legitimate Zoom links originate from
zoom.us; Teams fromteams.microsoft.com. Any variation is a flag. - Harden your endpoint. macOS is a documented BlueNoroff target. Keep security tooling current and resist the urge to relax Gatekeeper or SIP settings.
- Brief your team. The attack surface is whoever accepts calendar invites from industry contacts. A five-minute heads-up on this campaign is worth more than most security awareness training.
Priority call
Elevated for crypto and digital asset organizations. Standard phishing hygiene posture for everyone else — this is targeted infrastructure, not broad spray.
No patch applies here. The mitigation is operational: slow down before clicking meeting links, particularly from industry contacts you haven’t interacted with recently.
Sources
- The Hacker News, 2026-07-24: BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Found this useful? Share it.


