Threat Advisory

BlueNoroff Phishing Campaign Deploys Zoom Kit to Impersonate Videoconferencing Platforms

Threat: Phishing Campaign
Threat Actor Name: APT38
Threat Actor Type: Nation-Sponsored or State-Sponsored
Targeted Region: Global
Alias: G0082/G0032, Stardust Chollima, UNC1758/UNC1069/UNC4736 /TEMP.Hermit, Copernicium/Sapphire Sleet, TA444, TAG-71/Lazarus Group, ITG03/Hive0080, Void Arachne, Klipodenc, Black Dev 2, Black Alicanto, ATK117, CTG-6459, T-APT-15, APT-C-26, Group77, SectorA01, BeagleBoyz, NESTEGG
Threat Actor Region: North Korea
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

BlueNoroff, a threat actor associated with the broader Lazarus ecosystem, has developed an advanced phishing framework that abuses trusted relationships and impersonates legitimate video conferencing platforms to target cryptocurrency and Web3 organizations. The campaign uses fake Zoom and Microsoft Teams meeting invitations combined with social engineering techniques to deceive victims, gain their trust, and deliver malware through a ClickFix-based attack chain. The operation is designed to identify valuable targets by profiling cryptocurrency-related assets before deploying malicious payloads.

The attack chain begins with phishing messages sent from compromised trusted contacts, directing victims to fraudulent meeting pages designed to mimic legitimate conferencing services. These fake platforms display convincing meeting interfaces and prompt users with fake troubleshooting messages, such as software or SDK update requirements. The ClickFix technique is then used to manipulate clipboard content, causing victims to unknowingly execute attacker-controlled commands. On Windows systems, the campaign can deploy PowerShell-based loaders and VBScript implants, while the malware chain performs activities such as browser credential theft, Telegram session collection, cryptocurrency wallet reconnaissance, and additional payload delivery. The phishing kit also profiles victims’ environments to identify valuable cryptocurrency assets before proceeding with further exploitation.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

BlueNoroff, a threat actor associated with the broader Lazarus ecosystem, has developed an advanced phishing framework that abuses trusted relationships and impersonates legitimate video conferencing platforms to target cryptocurrency and Web3 organizations. The campaign uses fake Zoom and Microsoft Teams meeting invitations combined with social engineering techniques to deceive victims, gain their trust, and deliver malware through a ClickFix-based attack chain. The operation is designed to identify valuable targets by profiling cryptocurrency-related assets before deploying malicious payloads.

The attack chain begins with phishing messages sent from compromised trusted contacts, directing victims to fraudulent meeting pages designed to mimic legitimate conferencing services. These fake platforms display convincing meeting interfaces and prompt users with fake troubleshooting messages, such as software or SDK update requirements. The ClickFix technique is then used to manipulate clipboard content, causing victims to unknowingly execute attacker-controlled commands. On Windows systems, the campaign can deploy PowerShell-based loaders and VBScript implants, while the malware chain performs activities such as browser credential theft, Telegram session collection, cryptocurrency wallet reconnaissance, and additional payload delivery. The phishing kit also profiles victims’ environments to identify valuable cryptocurrency assets before proceeding with further exploitation.[emaillocker id="1283"]

It demonstrates an evolution of phishing operations by combining identity abuse, social engineering, malware delivery, and victim profiling into a coordinated attack framework. Organizations, especially those operating in cryptocurrency, financial services, and Web3 sectors, should strengthen phishing awareness, verify unexpected meeting invitations through trusted channels, restrict execution of suspicious scripts, and monitor for abnormal PowerShell, browser credential access, and session theft activities to reduce the risk of compromise.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Initial access T1566.003 Phishing Spearphishing via Service
Execution T1204.002 User Execution Malicious File
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Collection T1005 Data from Local System -
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu