블루노로프가 줌과 MS 팀을 사칭하여 암호화폐 지갑을 노리는 피싱 키트를 운영하고 있다.
북한의 해커 그룹 블루노로프가 줌과 마이크로소프트 팀을 사칭하는 피싱 키트를 운영하고 있다는 사실이 밝혀졌다. 이들은 타오픈 Zoom 및 Microsoft Teams 도메인을 사용하여 사회공학적 전술로 악성코드를 배포하고 있다. 관련 산업 연락망과 사회공학을 조합하여 신뢰 남용을 활용하고 있는 것으로 분석된다.
BlueNoroff operates a phishing kit impersonating Zoom and MS Teams to target crypto wallets.
The North Korean hacker group BlueNoroff has been found to operate a phishing kit that impersonates Zoom and Microsoft Teams. They use typosquatted domains to carry out social engineering campaigns aimed at delivering malware. By combining compromised industry contacts and social engineering tactics, they have operationalized trust abuse.