BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures

2026-04-29T02:51:45Z108c4268ee320864abbd463a37d41993cbabeec58a410b570e5c6522534e47f4
agentic-aiai-phishingblue-noroffbomgar-rmmbotnetsclickfixcloud-abusecve-2026-1731glasswormgoogle-antigravityinfostealerlazarusphantomrpcphishingransomwaresupply-chainunc6692vidarvs-code-extensionsvulnerabilitieswindows-defender-exploitwindows-privilege-escalationzealot

What happened

DarkReading roundup (Apr 16–28, 2026) highlights a surge in sophisticated, multi-vector campaigns and supply-chain abuse: North Korean BlueNoroff and related DPRK groups are using stolen videos, AI-generated avatars and fake Zoom/Zoom-update lures to scale attacks against crypto and high-value targets; GlassWorm attackers are seeding malicious VS Code extensions via Open VSX to propagate self‑propagating malware; and Vidar has reemerged as a dominant infostealer. Multiple APTs and criminal groups are abusing cloud collaboration tools (Teams, Slack, Outlook, Discord, S3) and novel vectors (home

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
108c4268ee320864abbd463a37d41993cbabeec58a410b570e5c6522534e47f4
Enrichment time
2026-04-29T02:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.