BlueNoroff, a threat actor associated with the broader Lazarus ecosystem, has developed an advanced phishing framework that abuses trusted relationships and impersonates legitimate video conferencing platforms to target cryptocurrency and Web3 organizations. The campaign uses fake Zoom and Microsoft Teams meeting invitations combined with social engineering techniques to deceive victims, gain their trust, and deliver malware through a ClickFix-based attack chain. The operation is designed to identify valuable targets by profiling cryptocurrency-related assets before deploying malicious payloads.
The attack chain begins with phishing messages sent from compromised trusted contacts, directing victims to fraudulent meeting pages designed to mimic legitimate conferencing services. These fake platforms display convincing meeting interfaces and prompt users with fake troubleshooting messages, such as software or SDK update requirements. The ClickFix technique is then used to manipulate clipboard content, causing victims to unknowingly execute attacker-controlled commands. On Windows systems, the campaign can deploy PowerShell-based loaders and VBScript implants, while the malware chain performs activities such as browser credential theft, Telegram session collection, cryptocurrency wallet reconnaissance, and additional payload delivery. The phishing kit also profiles victims’ environments to identify valuable cryptocurrency assets before proceeding with further exploitation.[/subscribe_to_unlock_form]
BlueNoroff, a threat actor associated with the broader Lazarus ecosystem, has developed an advanced phishing framework that abuses trusted relationships and impersonates legitimate video conferencing platforms to target cryptocurrency and Web3 organizations. The campaign uses fake Zoom and Microsoft Teams meeting invitations combined with social engineering techniques to deceive victims, gain their trust, and deliver malware through a ClickFix-based attack chain. The operation is designed to identify valuable targets by profiling cryptocurrency-related assets before deploying malicious payloads.
The attack chain begins with phishing messages sent from compromised trusted contacts, directing victims to fraudulent meeting pages designed to mimic legitimate conferencing services. These fake platforms display convincing meeting interfaces and prompt users with fake troubleshooting messages, such as software or SDK update requirements. The ClickFix technique is then used to manipulate clipboard content, causing victims to unknowingly execute attacker-controlled commands. On Windows systems, the campaign can deploy PowerShell-based loaders and VBScript implants, while the malware chain performs activities such as browser credential theft, Telegram session collection, cryptocurrency wallet reconnaissance, and additional payload delivery. The phishing kit also profiles victims’ environments to identify valuable cryptocurrency assets before proceeding with further exploitation.[emaillocker id="1283"]
It demonstrates an evolution of phishing operations by combining identity abuse, social engineering, malware delivery, and victim profiling into a coordinated attack framework. Organizations, especially those operating in cryptocurrency, financial services, and Web3 sectors, should strengthen phishing awareness, verify unexpected meeting invitations through trusted channels, restrict execution of suspicious scripts, and monitor for abnormal PowerShell, browser credential access, and session theft activities to reduce the risk of compromise.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Initial access | T1566.003 | Phishing | Spearphishing via Service |
| Execution | T1204.002 | User Execution | Malicious File |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Collection | T1005 | Data from Local System | - |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
The following reports contain further technical details:
[/emaillocker]