North Korean BlueNoroff Uses AI for Sophisticated Zoom Phishing Attacks

North Korean BlueNoroff Uses AI for Sophisticated Zoom Phishing Attacks

First seen 24 Jul 2026, 19:50 UTC ThehackernewsFeeds.4SysopsAiweekly.Cothehacker.news 87% similarity 72.5

Article Content

Browse articles
ThreatCluster

A North Korean cyber group, BlueNoroff, has developed a phishing kit that utilizes AI-generated faces to create convincing fake Zoom and Teams meetings targeting cryptocurrency executives. The kit employs pre-edited videos featuring deepfake headshots created with OpenAI's ChatGPT, enhancing its deception. Victims receive invites through compromised Telegram accounts of trusted contacts, leading them to typosquatted domains. Once engaged, the malware profiles installed cryptocurrency wallets and exfiltrates sensitive data. JUMPSEC identified five distinct versions of the kit between May 31 and July 14, 2026, indicating active development and refinement. This ongoing campaign poses significant risks to organizations relying on virtual meetings for critical transactions.

Key Points: • BlueNoroff's phishing kit uses AI-generated faces to deceive victims during fake meetings. • The kit targets high-value cryptocurrency executives by profiling installed wallets before malware delivery. • Five versions of the phishing kit were identified in a span of two weeks, indicating ongoing refinement.

ThreatCluster AI

Timeline

2026-05-31
First version of BlueNoroff phishing kit identified
The phishing kit was first detected, utilizing AI-generated faces for deception.
Feeds.4Sysops
2026-07-14
Fifth version of phishing kit discovered
JUMPSEC reported five distinct versions of the phishing kit, showcasing active development.
Aiweekly.Co
2026-07-25
Ongoing phishing campaign reported
The phishing kit continues to target cryptocurrency executives, leveraging deepfake technology.
The Hacker News

Community

Browse all →