BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
Campaign
Summary
Hide ▲
Show ▼
BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value crypto targets. The operation combines trusted-contact compromise, wallet reconnaissance, and self-propagating messaging to turn one account takeover into the next. The result is a repeatable victim-acquisition pipeline that raises the risk of account theft, malware infection, and follow-on targeting across the cryptocurrency sector.
Related Happenings
Famous Chollima ClickFake Interview recruitment scam campaign
Campaign
H score34
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...
Famous Chollima ClickFake Interview recruitment scam campaign
CampaignAbout this happening: A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...
Ghost Networks crypto-clipper promotion campaign
Campaign
H score15
First: 17.06.2026 21:14
Last: 17.06.2026 21:14
Sources 1
About this happening:
Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
Ghost Networks crypto-clipper promotion campaign
CampaignAbout this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
JINX-0164 cryptocurrency recruitment-lure campaign
Campaign
H score39
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
JINX-0164 cryptocurrency recruitment-lure campaign
CampaignAbout this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
North American cryptocurrency company hit by network compromise
Incident
H score31
First: 28.04.2026 11:00
Last: 28.04.2026 11:00
Sources 1
About this happening:
A North American cryptocurrency company suffered a multi-stage intrusion that began on January 23, 2026, and the attackers kept access for 66 days. The foothold ca...
North American cryptocurrency company hit by network compromise
IncidentAbout this happening: A North American cryptocurrency company suffered a multi-stage intrusion that began on January 23, 2026, and the attackers kept access for 66 days. The foothold ca...
Timeline
-
24.07.2026 18:12 2 articles · 4h ago
BlueNoroff impersonates Zoom and Microsoft Teams to deliver malware to crypto targets
Campaign Scope UpdateBlueNoroff operates a phishing kit that impersonates Zoom and Microsoft Teams in social-engineering campaigns aimed at high-ranking employees of major companies in the cryptocurrency space. The kit uses compromised Telegram accounts and trusted contacts to distribute Calendly links to fake meeting pages, profiles victims' cryptocurrency wallets before malware delivery, and the Teams variant adds emoji reaction support, mobile/tablet blocking, and advanced wallet probes; JUMPSEC said five kit versions were seen from May 31 to July 14, 2026.
Show sources
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery — thehackernews.com — 24.07.2026 18:12
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery — thehackernews.com — 24.07.2026 18:12