type: incident ยท created: 2026-07-26 ยท updated: 2026-07-26 ยท tags: [incident, nation-state, north-korea, bluenoroff, phishing, cryptocurrency, zoom, typosquatting, malware] ยท confidence: high ยท affected_sectors: [finance, technology] ยท au_impact: true
BlueNoroff (North Korea) Zoom Phishing Kit โ Crypto Wallet Profiling
BlueNoroff, a North Korean state-sponsored threat actor, has operationalised a sophisticated phishing platform that profiles victims' cryptocurrency wallets before delivering malware, enabling selective targeting of high-value victims.
Campaign Details
| Field | Detail |
|---|---|
| Threat Actor | BlueNoroff (North Korea) |
| Tactic | Typosquatted Zoom and Microsoft Teams domains |
| Technique | Wallet profiling before malware delivery |
| Target | Cryptocurrency holders and crypto industry personnel |
| Date | July 24, 2026 |
The phishing kit first assesses a victim's cryptocurrency holdings before deciding whether to deploy malware, allowing the attackers to focus on high-value targets while avoiding exposure on low-value contacts.
Related Actors
BlueNoroff is a subgroup of the larger Lazarus Group, North Korea's primary state-sponsored cyber threat organisation, focused on financial theft to fund the regime.
Source
- The Hacker News โ July 24, 2026