Context: A New Breed of Phishing Targets Crypto Users

According to a recent report covered by The Hacker News, a North Korean threat group called BlueNoroff has built an advanced phishing kit that mimics Zoom and Microsoft Teams. The attackers don’t just ask for passwords — they first check if a victim has cryptocurrency wallets installed in their browser, then only proceed with malware delivery if the target appears valuable.

What makes this campaign especially dangerous is its self-spreading design. After one victim runs the malicious code, the attackers steal that person’s Telegram account and use it to send faked meeting invites to the victim’s own trusted contacts. This creates a chain reaction that can quickly expand far beyond the initial target.

Why This Attack Method Is So Hard to Spot

The BlueNoroff kit uses multiple layers of deception that would fool even cautious users. Victims land on a convincing Zoom login page, grant camera access, and then see a realistic “waiting for others” screen — complete with a pre-recorded video of a familiar-looking person whose face was generated or stitched from previous attacks. The attacker can also send fake “your mic isn’t working” messages to trigger a fake software update, which is actually the malware download.

This approach bypasses many traditional security filters. The phishing pages look real because they are constantly updated — researchers found five different versions of the kit released in just six weeks. And because the invitation comes from a known contact’s hijacked Telegram account, the victim has no reason to suspect anything is wrong until it’s too late.

What This Means for Australian SMBs

Australian small and mid-sized businesses often handle payments, client funds, and internal communications through platforms like Zoom and Teams. While this specific campaign targets cryptocurrency wallet owners, the techniques can easily be adapted to steal credentials or install ransomware on any business network. An employee who handles company finances or has access to sensitive data is a prime target.

Because the attack relies on social engineering through trusted contacts, it can spread inside a company quickly. One compromised account could lead to a cascade of malware infections across the entire team. For SMBs with limited IT staff, detecting and stopping this kind of attack before it causes real damage is extremely difficult without proper preparation.

What You Can Do Now

  • Train all staff to verify unexpected meeting invitations — even if they appear to come from a colleague. A quick phone call or separate message can confirm the invite is real.
  • Require multi-factor authentication (MFA) on all business accounts, especially email, messaging apps like Telegram and Slack, and financial systems.
  • Disable or restrict browser extensions that manage cryptocurrency wallets on work devices. If crypto is not part of your business, there is no reason for those extensions to be installed.
  • Implement endpoint detection and response (EDR) software that can flag unusual PowerShell scripts or Chrome profile access, which are common in these attacks.
  • Create a clear incident response plan so that if an employee suspects they clicked a malicious link, they know exactly who to contact and what steps to take to limit the damage.

Cyber threats are evolving faster than ever, and Australian SMBs need practical guidance to stay safe. At MS&VG, we help businesses like yours assess their security posture, roll out smart protections, and build a culture of vigilance — without the technical overwhelm.