- North Korean threat actor BlueNoroff is running ClickFix-style campaigns using typosquatted Zoom and Microsoft Teams domains.
- The group operates an active phishing kit designed to impersonate videoconferencing platforms.
- These social engineering attacks aim to deliver malware, with a focus on cryptocurrency wallet compromise.
The North Korean threat actor known as BlueNoroff has been actively exploiting typosquatted Zoom and Microsoft Teams domains in ClickFix-style campaigns to deploy malware. Researchers discovered the group operates a sophisticated phishing kit that closely mimics the login interfaces of these videoconferencing platforms.
“BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet,” the report notes. Consequently, the attackers leverage these fake domains to trick users into downloading malicious payloads during seemingly routine meeting invitations. Meanwhile, the group’s tactics mirror previous campaigns that targeted cryptocurrency professionals and blockchain firms.
The phishing kit enables BlueNoroff to harvest credentials and deliver malware designed to drain digital wallets. Although the exact scale remains undisclosed, the campaign underscores a persistent threat to the crypto sector. Security experts urge organizations to verify domain authenticity before downloading any conferencing software.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
