#BlueNoroff
Inside a DPRK BlueNoroff ClickFix Kit
Inside a DPRK BlueNoroff ClickFix Kit
www.jumpsec.com
September 28, 2026 at 12:40 AM
Amazon、DebugとChalk NPMのサプライチェーン攻撃を北朝鮮のハッカーと関連付ける

Amazonは、Node Package Manager(npm)のエコシステムを標的とした複数の著名なオープンソースソフトウェアサプライチェーン攻撃を、北朝鮮のハッカーと関連付けた。

このクラウドコンピューティング大手は、typo-crypto、debug、chalk、およびaxiosライブラリの脆弱性を、BlueNoroffおよびStardust Chollimaとしても知られるSapphire Sleet脅威アクターに関連付けた。

最初の活動は、2025年3月にtypo-cryp...
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.
www.bleepingcomputer.com
August 30, 2026 at 1:49 PM
BlueNoroffの偽会議キットは、ウェブカメラをキャプチャし、Defenderを無効化し、暗号通貨の認証情報を盗み出す。

ラザルスグループと関連のある、金銭目的の脅威集団であるBlueNoroffが、非常に高度な「偽会議」フィッシングキットを展開していることが確認されている。

これは従来の誘い文句をはるかに超え、ウェブカメラのキャプチャ、Microsoft Defenderの回避、標的型暗号通貨認証情報の窃盗を可能にする。

JUMPSECによる新たな調査により、攻撃者が誤って稼働中のインフラストラクチャ上でJavaScriptのソースマップを公開した後、その操作に関するソースレ...
BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit.
gbhackers.com
August 25, 2026 at 10:05 PM
Kaspersky GReAT identifies Bluenoroff link in major supply chain attack

Researchers from Kaspersky’s Global Research and Analysis Team (GReAT) uncovered technical links between the headline-grabbing supply chain attack on Axios, one of the world’s most widely used JavaScript libraries, and…
Kaspersky GReAT identifies Bluenoroff link in major supply chain attack
Researchers from Kaspersky’s Global Research and Analysis Team (GReAT) uncovered technical links between the headline-grabbing supply chain attack on Axios, one of the world’s most widely used JavaScript libraries, and previously documented campaigns associated with BlueNoroff, a financially motivated subgroup of the infamous Lazarus Group. Axios is one of the most widely used JavaScript HTTP [...] The post Kaspersky GReAT identifies Bluenoroff link in major supply chain attack appeared first on NCN Online .
news-area.com
August 17, 2026 at 11:58 PM
➤ North Korean hacking group BlueNoroff (also known as UNC1069) is targeting cryptocurrency professionals by hijacking Telegram accounts.
August 8, 2026 at 4:27 PM
Bitcoin Telegram accounts targeted by North Korean hackers
Aug 07 2026 12:11 UTC
BlueNoroff is hijacking Telegram accounts and using fake Zoom and Teams meetings to deliver malware targeting Bitcoin and crypto professionals.
#north-korea #blue-noroff #telegram #bitcoin #cryptocurrency #zoom
August 8, 2026 at 4:27 PM
🔍 BlueNoroff convierte contactos de Telegram en señuelos para robar criptos.


https://x.com/WhisprNews/status/2085803505160196
526
August 8, 2026 at 10:41 AM
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TAG-195 Upgrades MaaS Ecosystem with Modular Tools  Inside a DPRK BlueNoroff Clic…
#hackernews #news
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TAG-195 Upgrades MaaS Ecosystem with Modular Tools  Inside a DPRK BlueNoroff ClickFix Kit SourTrade: Browser-Assembled Malware Delivered Through Malvertising   MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions   Unpacking “Cruciferra”: An Analysis of a […]
securityaffairs.com
August 3, 2026 at 2:45 PM
"Tearing Down a DPRK-Linked macOS Crypto Stealer"

Tonmoy Jitu unpacks a Lazarus/BlueNoroff macOS campaign, from Gatekeeper bypasses to credential theft and an exposed C2 API that revealed the operators' workflow.

cfp.bsidescbr.com.au/bsides-canbe...
Tearing Down a DPRK-Linked macOS Crypto Stealer BSides Canberra 2026
This talk presents a technical analysis of a multi-stage macOS attack chain attributed with moderate-high confidence to the Lazarus/BlueNoroff cluster, targeting cryptocurrency users across a broad ra...
cfp.bsidescbr.com.au
July 31, 2026 at 6:43 AM
JUMPSEC analyzed the BlueNoroff phishing kit's source code. The DPRK ClickFix attack fakes Zoom and Teams calls to profile and drain crypto wallets.

#BlueNoroff #ClickFix #Lazarus #CryptoTheft
BlueNoroff Phishing Kit Turns Fake Zoom and Teams Calls Into a Crypto Wallet Theft Machine
At a glance
securityonline.info
July 30, 2026 at 6:40 AM
BlueNoroffは偽のZoom通話で暗号通貨ウォレットをスキャンしてからマルウェアをばらまく
Cryptopolitan

JUMPSECは、流出したコードの中に不完全なGoogle Meetクローンも発見した。. すべてのオペレーティングシステムには、専用のマルウェアペイロードが存在する …
www.cryptopolitan.com/ja/bluenorof...
BlueNoroffは偽のZoom通話で暗号通貨ウォレットをスキャンしてからマルウェアをばらまく
北朝鮮のBlueNoroffは、マルウェアを仕掛ける前に、偽のZoomやTeamsの通話で暗号通貨ウォレットをスキャンしていることが、JUMPSECの調査で判明した。.
www.cryptopolitan.com
July 28, 2026 at 1:07 PM
North Korean group BlueNoroff is using fake Zoom and Teams phishing kits to profile crypto wallets and deliver malware. They're exploiting trusted communications platforms to…

https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html

#cybersecurity #infosec
July 28, 2026 at 12:00 PM
Contact Telegram détourné, invite en visio, fausse mise à jour Zoom, et tes wallets crypto se vident. BlueNoroff, zéro faille.

👉 https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html
👉 https://macsouverain.com/radar-bluenoroff-zoom-sdk-update-macos/

#MacSouverain #macOS
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
BlueNoroff uses fake Zoom and Teams meetings to profile crypto wallets, hijack Telegram accounts, and deliver Windows and macOS malware.
thehackernews.com
July 28, 2026 at 10:25 AM
Five APTs defined H1 2026: BlueNoroff fakes your Zoom invite, Volt Typhoon brings no malware at all. https://intel.threadlinqs.com/threat/TL-2026-1721 #ThreatIntel #CVE_2023_27997 #CVE_2024_39717 #RustBucket
July 27, 2026 at 4:37 PM
North Korea's BlueNoroff Uses Fake Zoom Platform to Spread Malware
North Korean hacking group BlueNoroff, a subgroup under the broader Lazarus Group ecosystem, has escalated its social engineering operations across the Web3 sector. New findings from cybersecurity firm JUMPSEC reveal that the group is operating an active, highly structured phishing kit impersonating Zoom and Microsoft Teams. Rather than infecting every user who interacts with the lure, the kit selectively targets high-value cryptocurrency holders after scanning their browsers for crypto wallet extensions. How the attack works The scam starts with a message sent from a compromised Telegram account belonging to someone the victim already knows, often a trusted contact in the cryptocurrency industry. The victim receives what looks like a legitimate Calendly invitation for a Zoom meeting. But instead of taking them to Zoom, the link redirects them to a fake website hosted on a typosquatted domain that closely mimics the real video conferencing platform. The phishing page asks users to enter their name and grant webcam access. Behind the scenes, the webcam feed is quietly transmitted to the attackers. Once the victim joins the fake meeting, they see a “waiting for other participants” screen while the attackers control the session from an operator panel. The operators then send fake messages...
www.cryptotimes.io
July 27, 2026 at 2:55 PM
North Korean Hackers Use AI-Powered Scams to Steal Millions in Cryptocurrency
North Korean Hackers Use AI-Powered Scams to Steal Millions in Cryptocurrency
BlueNoroff uses fake Zoom and Microsoft Teams calls with AI-generated headshots to steal crypto wallets targeting 100+ victims globally including 41% in the US.
growmybag.tv
July 27, 2026 at 10:10 AM
BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls

cybersecuritynews.com/bluenoroff-h...

#Kyberturvallisuus #ThreatIntel #Haavoittuvuus
BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls
BlueNoroff hijacks Telegram accounts to send fake Zoom and Teams links, stealing crypto wallets, credentials, and funds via ClickFix.
cybersecuritynews.com
July 27, 2026 at 9:06 AM
JUMPSEC analysed source code from an active BlueNoroff phishing kit used to impersonate Zoom & Microsoft Teams meetings. Operators mistakenly exposed JS source maps on live infrastructure, giving researchers source-level insight into how the operation works. www.jumpsec.com/guides/insid...
July 27, 2026 at 8:57 AM
BlueNoroff runs a deepfake Zoom call, then your clipboard pastes the malware for them. https://intel.threadlinqs.com/threat/TL-2026-1720 #ThreatIntel #TrojanNukeSped #TrojanSLoad #ClickFix
July 27, 2026 at 8:31 AM