Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
BlueNoroff Targets Crypto Wallets via Phishing on Zoom

BlueNoroff Targets Crypto Wallets via Phishing on Zoom

Posted on July 24, 2026 By CWS

North Korean cybercriminals under the BlueNoroff group have been leveraging fake domains mimicking Zoom and Microsoft Teams to execute phishing campaigns aimed at delivering malware. These meticulously orchestrated schemes are part of a broader strategy to exploit trust and infiltrate cryptocurrency wallets.

How BlueNoroff Executes Its Phishing Schemes

According to a detailed analysis by JUMPSEC, BlueNoroff’s operations involve a sophisticated blend of social engineering and technical manipulation. They initiate the attack by utilizing compromised contacts within the industry to gain initial access and then establish a self-propagating chain of attacks through Telegram. The process involves profiling the cryptocurrency wallets of potential victims before deploying malware, allowing them to selectively target valuable targets.

JUMPSEC’s report outlines how the attackers use legitimate-looking Telegram messages to distribute deceptive meeting links to unsuspecting targets. These links lead to a fake Zoom page where victims are tricked into granting webcam permissions, which are then hijacked by the attackers. This methodical approach enables the attackers to maintain a continuous cycle of account compromises.

Technical Execution and Tools Used

The phishing kit crafted by BlueNoroff employs a multi-step process that begins with a seemingly authentic meeting link and ends with the deployment of the ClickFix payload. The attack is tailored to both Windows and macOS systems, with each variant executing specific commands to harvest sensitive data. On Windows, a PowerShell loader is used to disable security measures and identify high-value crypto wallet extensions, while on macOS, a fake installer extracts crucial information and sends it to the attackers via Telegram.

Further investigation revealed that the phishing kit is under active development, with multiple versions surfacing between May and July 2026. This indicates ongoing refinements to enhance the effectiveness of their campaigns, specifically targeting Zoom and Teams environments due to their prevalence in the finance and cryptocurrency sectors.

Potential Implications and Future Outlook

Sean Moran, JUMPSEC’s head of threat research, highlighted that BlueNoroff’s focus on Zoom and Teams exploits specific user expectations of these platforms having desktop applications. The familiar appearance of their fake links increases the likelihood of successful deception. Despite the current focus, there is evidence of potential expansion to other platforms like Google Meet, though this remains unimplemented for now.

The campaign underscores the evolving threat landscape facing digital assets and the importance of securing communication channels and individual identities. As BlueNoroff continues to refine its tactics, organizations must prioritize comprehensive security strategies that address not only technical vulnerabilities but also human factors in cybersecurity.

The Hacker News Tags:BlueNoroff, ClickFix, Crypto, Cryptocurrency, Cybersecurity, digital security, identity theft, Malware, Microsoft Teams, North Korea, Phishing, social engineering, Telegram, Threat Actors, Zoom

Post navigation

Previous Post: ChonkyChicken Malware Targets Chrome Credentials
Next Post: Cl0p Hackers Target Windchill Servers for Data Theft

Related Posts

Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown The Hacker News
Forg365 PhaaS Exploits Microsoft 365 with Advanced Tactics Forg365 PhaaS Exploits Microsoft 365 with Advanced Tactics The Hacker News
Enhancing Security: From Visibility to Validation Enhancing Security: From Visibility to Validation The Hacker News
CISA Highlights Six Exploited Flaws in Major Software CISA Highlights Six Exploited Flaws in Major Software The Hacker News
New FileFix Method Emerges as a Threat Following 517% Rise in ClickFix Attacks New FileFix Method Emerges as a Threat Following 517% Rise in ClickFix Attacks The Hacker News
GPT-5 Agent That Finds and Fixes Code Flaws Automatically GPT-5 Agent That Finds and Fixes Code Flaws Automatically The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats
  • Cl0p Hackers Target Windchill Servers for Data Theft
  • BlueNoroff Targets Crypto Wallets via Phishing on Zoom
  • ChonkyChicken Malware Targets Chrome Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats
  • Cl0p Hackers Target Windchill Servers for Data Theft
  • BlueNoroff Targets Crypto Wallets via Phishing on Zoom
  • ChonkyChicken Malware Targets Chrome Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark