BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

Summary

North Korean threat actors, BlueNoroff, are actively using a phishing kit to impersonate Zoom and Microsoft Teams. This kit profiles cryptocurrency wallets before delivering malware, indicating a sophisticated social engineering approach.

IFF Assessment

FOE

This activity represents an advanced social engineering technique by a known threat actor, posing a direct risk to users and organizations.

Defender Context

Defenders should be aware of sophisticated phishing campaigns targeting users with the guise of legitimate communication platforms like Zoom and Teams. Vigilance against typosquatted domains and scrutiny of any requests related to cryptocurrency transactions are crucial to prevent malware infections.

Read Full Story →