THREAT OPS › Threat News › BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.
"BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet
Attributed threat actors
- APT38G0082
MITRE ATT&CK techniques
- Social EngineeringT1684