North Korean threat actors linked to BlueNoroff are running a targeted phishing campaign that impersonates Zoom and Microsoft Teams to compromise victims in the cryptocurrency sector. Researchers said the operation abuses hijacked Telegram accounts belonging to trusted real-world contacts, sending fake Calendly and meeting links that lead targets into staged video calls. The phishing kit captures webcam images, fingerprints browsers, checks for cryptocurrency-wallet indicators, and selectively advances only high-value victims to the next stage. Investigators also observed at least five versions of the kit between late May and mid-July, indicating active development and refinement.
The campaign supports both Windows and macOS and uses a ClickFix-style lure to trick victims into executing malicious commands themselves. Reported post-click activity on Windows includes a PowerShell loader, a VBScript implant launched through wscript.exe, attempts to add Microsoft Defender exclusions, checks for Telegram sessions, and enumeration of browser extensions before possible follow-on payload delivery. Researchers also found the actors using AI-generated headshots composited onto authentic body movements from prior victims to make fake meetings appear convincing, turning routine video-call invitations into a highly selective malware-delivery pipeline.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
JUMPSEC analyzed a BlueNoroff social-engineering campaign that hijacks real Telegram accounts to send fake Zoom and Microsoft Teams meeting links to cryptocurrency and Web3 targets. The operation used ClickFix-style prompts and distinct Windows and macOS infection chains, with compromised Telegram sessions enabling further victim outreach.
JUMPSEC reported that the latest of at least five observed versions of BlueNoroff's phishing kit was seen on July 14, 2026. The kit impersonates Zoom and Microsoft Teams to profile cryptocurrency-sector victims before malware delivery.
JUMPSEC observed at least five versions of BlueNoroff's Zoom/Teams-themed phishing kit, indicating active development of the operation. The observed versions span from May 31 to July 14, 2026.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 99 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcetrojan-killer.net
Open sourcethehackernews.com
Open sourcejumpsec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.