Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, apt-group, stealer] ยท confidence: high ยท affected_sectors: [technology, finance] ยท au_impact: false

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

North Korean BlueNoroff actors have operationalised an operator-driven phishing kit that profiles victims' cryptocurrency wallets before delivering malware. The campaign uses typosquatted Zoom and Microsoft Teams domains with compromised trusted contacts as initial access.

Overview

Attribute Detail
Date 2026-07-24
Threat Actor BlueNoroff (North Korea-linked APT)
Campaign Type Targeted phishing with pre-delivery profiling
Initial Access Typosquatted Zoom/Microsoft Teams domains + compromised trusted contacts
Target Cryptocurrency wallet holders

Attack Chain

  1. Attacker compromises trusted contacts or typosquats video-conferencing domains
  2. Victim is profiled for cryptocurrency wallet presence and value
  3. Only high-value targets receive malware delivery
  4. Malware is deployed post-profiling

Significance

BlueNoroff is a subgroup of the larger Lazarus Group, focused on cryptocurrency theft to generate revenue for the North Korean regime. The addition of pre-delivery wallet profiling represents an operational sophistication upgrade โ€” attackers now assess target value before committing resources to malware delivery.

Related Pages