Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-26 ยท updated: 2026-07-26 ยท tags: [incident, nation-state, north-korea, bluenoroff, phishing, cryptocurrency, zoom, typosquatting, malware] ยท confidence: high ยท affected_sectors: [finance, technology] ยท au_impact: true

BlueNoroff (North Korea) Zoom Phishing Kit โ€” Crypto Wallet Profiling

BlueNoroff, a North Korean state-sponsored threat actor, has operationalised a sophisticated phishing platform that profiles victims' cryptocurrency wallets before delivering malware, enabling selective targeting of high-value victims.

Campaign Details

Field Detail
Threat Actor BlueNoroff (North Korea)
Tactic Typosquatted Zoom and Microsoft Teams domains
Technique Wallet profiling before malware delivery
Target Cryptocurrency holders and crypto industry personnel
Date July 24, 2026

The phishing kit first assesses a victim's cryptocurrency holdings before deciding whether to deploy malware, allowing the attackers to focus on high-value targets while avoiding exposure on low-value contacts.

Related Actors

BlueNoroff is a subgroup of the larger Lazarus Group, North Korea's primary state-sponsored cyber threat organisation, focused on financial theft to fund the regime.

Source