BlueNoroff Zoom/Teams Phishing Kit Campaign
First seen Jul 25, 2026 · Updated Jul 25, 2026
BlueNoroff, a North Korean state-sponsored threat actor, is operating an active phishing kit that impersonates Zoom and Microsoft Teams via typosquatted domains and ClickFix-style social engineering lures. The campaign profiles victims' cryptocurrency wallets before delivering malware, combining compromised industry contacts and trust abuse to maximize infection success.
Technical Analysis
The campaign leverages typosquatted domains mimicking Zoom and Microsoft Teams to lure victims into fake meeting invites, using ClickFix-style prompts that trick users into executing malicious commands (often via clipboard-paste-and-run PowerShell or terminal instructions) under the guise of fixing a connection or audio issue. Prior to malware deployment, the kit performs reconnaissance to profile victims' cryptocurrency wallet holdings, allowing operators to prioritize high-value targets for follow-on malware and wallet-draining payloads. The attack chain relies heavily on compromised industry contacts and social engineering rather than software exploits, making it effective against organizations in crypto, fintech, and Web3 sectors. Any host compromised through this vector—including developer or DevOps workstations—could expose API keys, cloud credentials, and session tokens used by AI agents or automation pipelines, enabling lateral movement into agent-integrated systems and RAG/tool-use infrastructure that share credentials with the victim machine.
Affected Systems
Windows and macOS endpoints used for videoconferencing (Zoom, Microsoft Teams clients), cryptocurrency wallet software, browser-based crypto extensions, and developer/DevOps workstations with stored credentials or API keys
Indicators of Compromise
- Typosquatted domains impersonating Zoom and Microsoft Teams (specific domains not disclosed in source)
- ClickFix-style fake meeting/connectivity error prompts
- Malicious PowerShell/terminal execution via clipboard-paste social engineering
- Phishing kit infrastructure attributed to BlueNoroff (Lazarus subgroup)
Remediation Steps
- 1
Block typosquatted domains
Deploy DNS filtering and threat intelligence feeds to identify and block known typosquatted Zoom/Teams domains associated with BlueNoroff infrastructure.
- 2
User awareness training
Train employees, especially those in crypto/fintech roles, to recognize ClickFix social engineering tactics and never paste/execute commands from meeting prompts.
- 3
Restrict script execution
Implement application control (AppLocker/WDAC) to prevent unauthorized PowerShell or terminal command execution triggered via clipboard paste.
- 4
Credential and API key rotation
Rotate API keys, cloud credentials, and session tokens on any endpoint suspected of compromise, particularly those used by automation or AI agent pipelines.
- 5
Wallet and crypto asset monitoring
Monitor cryptocurrency wallets for unauthorized access or draining activity and enforce hardware wallet/MFA protections for high-value holdings.
- 6
Endpoint detection and response
Deploy EDR tooling to detect ClickFix-style execution patterns and unusual process spawning from browser or conferencing applications.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.