type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, apt-group, stealer] ยท confidence: high ยท affected_sectors: [technology, finance] ยท au_impact: false
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
North Korean BlueNoroff actors have operationalised an operator-driven phishing kit that profiles victims' cryptocurrency wallets before delivering malware. The campaign uses typosquatted Zoom and Microsoft Teams domains with compromised trusted contacts as initial access.
Overview
| Attribute | Detail |
|---|---|
| Date | 2026-07-24 |
| Threat Actor | BlueNoroff (North Korea-linked APT) |
| Campaign Type | Targeted phishing with pre-delivery profiling |
| Initial Access | Typosquatted Zoom/Microsoft Teams domains + compromised trusted contacts |
| Target | Cryptocurrency wallet holders |
Attack Chain
- Attacker compromises trusted contacts or typosquats video-conferencing domains
- Victim is profiled for cryptocurrency wallet presence and value
- Only high-value targets receive malware delivery
- Malware is deployed post-profiling
Significance
BlueNoroff is a subgroup of the larger Lazarus Group, focused on cryptocurrency theft to generate revenue for the North Korean regime. The addition of pre-delivery wallet profiling represents an operational sophistication upgrade โ attackers now assess target value before committing resources to malware delivery.
Related Pages
- Golden Chickens Resurfaces With Four New Malware Families โ Parallel malware ecosystem development by TAG-195