BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures
2026-04-29T02:51:45Z•108c4268ee320864abbd463a37d41993cbabeec58a410b570e5c6522534e47f4
agentic-aiai-phishingblue-noroffbomgar-rmmbotnetsclickfixcloud-abusecve-2026-1731glasswormgoogle-antigravityinfostealerlazarusphantomrpcphishingransomwaresupply-chainunc6692vidarvs-code-extensionsvulnerabilitieswindows-defender-exploitwindows-privilege-escalationzealot
What happened
DarkReading roundup (Apr 16–28, 2026) highlights a surge in sophisticated, multi-vector campaigns and supply-chain abuse: North Korean BlueNoroff and related DPRK groups are using stolen videos, AI-generated avatars and fake Zoom/Zoom-update lures to scale attacks against crypto and high-value targets; GlassWorm attackers are seeding malicious VS Code extensions via Open VSX to propagate self‑propagating malware; and Vidar has reemerged as a dominant infostealer. Multiple APTs and criminal groups are abusing cloud collaboration tools (Teams, Slack, Outlook, Discord, S3) and novel vectors (home
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 108c4268ee320864abbd463a37d41993cbabeec58a410b570e5c6522534e47f4
- Enrichment time
- 2026-04-29T02:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.