🟠 High  |  Source: The Hacker News


North Korean threat group BlueNoroff is running an active phishing kit that impersonates Zoom and Microsoft Teams to target individuals holding cryptocurrency, profiling crypto wallets before delivering malware. The campaign combines compromised industry contacts with social engineering to establish trust before the attack is launched. This represents a sophisticated, multi-stage operation with significant financial theft potential, particularly for organisations in the crypto and Web3 sectors.

Security Architect’s Take: Enforce strict domain verification policies and deploy DNS filtering to block typosquatted domains mimicking Zoom and Teams. Review browser isolation controls and ensure endpoint detection tooling is tuned to flag suspicious wallet-related reconnaissance activity originating from meeting platform lookalikes.

Original advisory: BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery