Skip to content
feed: live
>_ 0dayNews
threat intel
● Breaking

BlueNoroff Active: Zoom Phishing Profiles Crypto Wallets

North Korea's BlueNoroff is running an active phishing kit impersonating Zoom and Teams. Campaign profiles wallets before malware delivery. Confirmed.

BlueNoroff Active: Zoom Phishing Profiles Crypto Wallets
Image: 0dayNews / 0dayNews Editorial · All rights reserved
airgap airgap · Published · 2 min read

Active. North Korea’s BlueNoroff cluster is operating a phishing kit that impersonates Zoom and Microsoft Teams, with wallet profiling built into the delivery chain before any malware drops. The Hacker News reported on July 24 with campaign details. Confidence: confirmed.

What’s confirmed

BlueNoroff — the DPRK-linked cluster behind documented ClickFix-style campaigns using typosquatted Zoom and Microsoft Teams domains — has operationalized a phishing kit combining three elements in sequence: compromised industry contacts as the initial outreach vector, fake videoconferencing pages for credential capture, and active wallet profiling before committing to payload delivery.

The profiling step is the operational tell here. The kit does not fire malware at every victim. It establishes asset value first. Targets below an unspecified threshold: dropped or deprioritized. Targets worth the follow-through: receive the payload. Confidence on the profiling mechanism: confirmed per reporting. Confidence on the threshold criteria or drop behavior: unconfirmed — not disclosed in current public reporting.

DPRK attribution: confirmed per The Hacker News reporting. BlueNoroff is the same cluster behind prior ClickFix-style campaigns using typosquatted meeting domains.

How the chain works

  • Initial contact: Outreach originates from compromised accounts belonging to real industry contacts. The sender identity is legitimate. The account is not.
  • Lure: Victims are directed to typosquatted domains impersonating Zoom and Microsoft Teams. Visual inspection of a meeting link is insufficient — the domains are designed to pass a quick look.
  • Profiling gate: Before payload delivery, the kit evaluates the target’s cryptocurrency holdings. Selection criteria: unconfirmed.
  • Delivery: Malware delivered to selected targets post-profiling. Specific malware families tied to this campaign’s current payloads: not disclosed in current public reporting.

What to watch for

This cluster does not cold-call strangers. The initial contact comes from a known name — a colleague, a recruiter, a counterpart in an industry network — whose account has been compromised. That’s the social engineering lever: the trust exists because the relationship exists.

If you work in cryptocurrency, DeFi, or adjacent financial technology:

  • Out-of-band verification before clicking. Meeting links arriving in email or DMs from known contacts warrant a direct check — text, call, separate message thread — before following the link.
  • Address bar, not display text. Typosquatted Zoom and Teams domains are built to pass visual inspection of the link text. Check the actual domain loaded in your browser.
  • Wallet exposure. This campaign profiles wallet value before targeting. Individuals and organizations with significant on-chain holdings are the explicit target category, not a coincidental one.

Ongoing development: watch for specific indicators of compromise and malware family attribution as researchers publish further analysis. The Hacker News report is the current primary source — link in sources below.


Source: BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery — The Hacker News, July 24, 2026.

Found this useful? Share it.