BlueNoroff Threat Actors Use Zoom Phishing Kits to Target Crypto Wallets with AI-Enhanced Social Engineering
BlueNoroff threat actors use Zoom phishing kits to profile cryptocurrency wallets through AI-enhanced social engineering before deploying malware. The campaign leverages compromised Telegram accounts, fake video calls with AI-generated avatars, and targeted wallet reconnaissance to enable selective malware delivery on Windows and macOS.
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.
"BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet
*** END OF TRANSMISSION ***