Find notable cyber news and cases, enriched with sources, timelines, and signals.

BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign

Campaign
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value crypto targets. The operation combines trusted-contact compromise, wallet reconnaissance, and self-propagating messaging to turn one account takeover into the next. The result is a repeatable victim-acquisition pipeline that raises the risk of account theft, malware infection, and follow-on targeting across the cryptocurrency sector.

Related Happenings

Famous Chollima ClickFake Interview recruitment scam campaign

Campaign
H score34 First: 21.07.2026 12:30 Last: 21.07.2026 12:30 Sources 1

About this happening: A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...

Ghost Networks crypto-clipper promotion campaign

Campaign
H score15 First: 17.06.2026 21:14 Last: 17.06.2026 21:14 Sources 1

About this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...

GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations

Campaign
H score39 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...

JINX-0164 cryptocurrency recruitment-lure campaign

Campaign
H score39 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...

North American cryptocurrency company hit by network compromise

Incident
H score31 First: 28.04.2026 11:00 Last: 28.04.2026 11:00 Sources 1

About this happening: A North American cryptocurrency company suffered a multi-stage intrusion that began on January 23, 2026, and the attackers kept access for 66 days. The foothold ca...

Timeline

  1. 24.07.2026 18:12 2 articles · 4h ago

    BlueNoroff impersonates Zoom and Microsoft Teams to deliver malware to crypto targets

    Campaign Scope Update

    BlueNoroff operates a phishing kit that impersonates Zoom and Microsoft Teams in social-engineering campaigns aimed at high-ranking employees of major companies in the cryptocurrency space. The kit uses compromised Telegram accounts and trusted contacts to distribute Calendly links to fake meeting pages, profiles victims' cryptocurrency wallets before malware delivery, and the Teams variant adds emoji reaction support, mobile/tablet blocking, and advanced wallet probes; JUMPSEC said five kit versions were seen from May 31 to July 14, 2026.

    Show sources