highPhishing

BlueNoroff Zoom/Teams Phishing Kit Campaign

First seen Jul 25, 2026 · Updated Jul 25, 2026

BlueNoroffNorth-KoreaAPTClickFixcrypto-theftsocial-engineeringtyposquattingwallet-draineragent-relevant

BlueNoroff, a North Korean state-sponsored threat actor, is operating an active phishing kit that impersonates Zoom and Microsoft Teams via typosquatted domains and ClickFix-style social engineering lures. The campaign profiles victims' cryptocurrency wallets before delivering malware, combining compromised industry contacts and trust abuse to maximize infection success.

Technical Analysis

The campaign leverages typosquatted domains mimicking Zoom and Microsoft Teams to lure victims into fake meeting invites, using ClickFix-style prompts that trick users into executing malicious commands (often via clipboard-paste-and-run PowerShell or terminal instructions) under the guise of fixing a connection or audio issue. Prior to malware deployment, the kit performs reconnaissance to profile victims' cryptocurrency wallet holdings, allowing operators to prioritize high-value targets for follow-on malware and wallet-draining payloads. The attack chain relies heavily on compromised industry contacts and social engineering rather than software exploits, making it effective against organizations in crypto, fintech, and Web3 sectors. Any host compromised through this vector—including developer or DevOps workstations—could expose API keys, cloud credentials, and session tokens used by AI agents or automation pipelines, enabling lateral movement into agent-integrated systems and RAG/tool-use infrastructure that share credentials with the victim machine.

Affected Systems

Windows and macOS endpoints used for videoconferencing (Zoom, Microsoft Teams clients), cryptocurrency wallet software, browser-based crypto extensions, and developer/DevOps workstations with stored credentials or API keys

Indicators of Compromise

  • Typosquatted domains impersonating Zoom and Microsoft Teams (specific domains not disclosed in source)
  • ClickFix-style fake meeting/connectivity error prompts
  • Malicious PowerShell/terminal execution via clipboard-paste social engineering
  • Phishing kit infrastructure attributed to BlueNoroff (Lazarus subgroup)

Remediation Steps

  1. 1

    Block typosquatted domains

    Deploy DNS filtering and threat intelligence feeds to identify and block known typosquatted Zoom/Teams domains associated with BlueNoroff infrastructure.

  2. 2

    User awareness training

    Train employees, especially those in crypto/fintech roles, to recognize ClickFix social engineering tactics and never paste/execute commands from meeting prompts.

  3. 3

    Restrict script execution

    Implement application control (AppLocker/WDAC) to prevent unauthorized PowerShell or terminal command execution triggered via clipboard paste.

  4. 4

    Credential and API key rotation

    Rotate API keys, cloud credentials, and session tokens on any endpoint suspected of compromise, particularly those used by automation or AI agent pipelines.

  5. 5

    Wallet and crypto asset monitoring

    Monitor cryptocurrency wallets for unauthorized access or draining activity and enforce hardware wallet/MFA protections for high-value holdings.

  6. 6

    Endpoint detection and response

    Deploy EDR tooling to detect ClickFix-style execution patterns and unusual process spawning from browser or conferencing applications.

Industries Most Exposed

CryptocurrencyFinancial ServicesWeb3/BlockchainTechnologyVenture Capital

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.