BlueNoroff Enhances Zoom Phishing Kit with Crypto Wallet Profiling and Deepfakes

BlueNoroff Enhances Zoom Phishing Kit with Crypto Wallet Profiling and Deepfakes

First seen 24 Jul 2026, 19:50 UTC ThehackernewsFeeds.4Sysopsthehacker.news 89% similarity 66.5

Article Content

Browse articles
ThreatCluster

BlueNoroff has upgraded its phishing kit targeting Zoom and Microsoft Teams, with five versions identified from May 31 to July 14, 2026. The kit now includes browser fingerprinting to detect installed cryptocurrency wallets, enabling attackers to focus on high-value targets. Phishing attempts are executed through typosquatted meeting links sent via hijacked Telegram accounts of trusted cryptocurrency contacts. More than 950 files are hosted on media servers associated with this campaign. This targeted approach raises concerns for enterprise leaders in the cryptocurrency sector. The ongoing evolution of this phishing kit indicates a significant threat to users of these platforms.

Key Points: • BlueNoroff's phishing kit has five updated versions identified since late May 2026. • The kit profiles cryptocurrency wallets to prioritize high-value victims. • Phishing links are sent via hijacked Telegram accounts of trusted contacts.

ThreatCluster AI

Timeline

2026-05-31
First version of BlueNoroff phishing kit identified
The initial version of the phishing kit targeting Zoom and Microsoft Teams was detected.
Feeds.4Sysops
2026-07-14
Five versions of phishing kit identified
Researchers identified a total of five versions of the BlueNoroff phishing kit within a short timeframe.
Feeds.4Sysops
2026-07-24
Current status of BlueNoroff phishing kit
The phishing kit continues to evolve, posing a significant threat to cryptocurrency users and enterprises.
Thehackernews

Community

Browse all →