BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. "BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet
Source: The Hacker News · July 24, 2026 at 11:01 PM · AI-assisted report
KUALA LUMPUR, 25 JULY 2026 —
Listen to this article
DomainFork Audio · read aloud
KUALA LUMPUR, July 24 - North Korean threat actors, known as BlueNoroff, have been found to operate an active phishing kit that impersonates videoconferencing platforms Zoom and Microsoft Teams. The phishing kit is used in social engineering campaigns designed to deliver malware, according to a report by The Hacker News. The threat actors employ typosquatted domains of the popular platforms to trick victims into divulging sensitive information.
The discovery of the BlueNoroff phishing kit is significant for Malaysia as it highlights the growing threat of cyber attacks targeting individuals and businesses in the country. Details not yet available on the extent of the phishing kit's impact in Malaysia, but the threat is likely to be a concern for local businesses and individuals who use videoconferencing platforms for work and communication. The Malaysian public is advised to be cautious when receiving emails or messages that appear to be from Zoom or Microsoft Teams.
Related: Microsoft