Zoom & doom: BlueNoroff call opens the door

2025-06-20 Field Effect

https://fieldeffect.com/blog/zoom-doom-bluenoroff-call-opens-the-door

Thumbnail for Zoom & doom: BlueNoroff call opens the door

Field Effect investigated a compromise at a Canadian online gambling provider that it says may be associated with BlueNoroff, a financially motivated North Korean Lazarus subgroup. The victim joined a cryptocurrency-related Zoom meeting with an impersonated trusted contact and was prompted to run a fake Zoom audio repair script that hid malicious curl and zsh commands after thousands of blank lines. The macOS infection chain downloaded scripts from zoom-tech[.]us, collected the user's local password, used sudo, staged malware under Apple-like filenames, and installed LaunchDaemon persistence for privileged execution. Follow-on components communicated with infrastructure including ajayplamingo[.]com, ajayplamingop[.]com, and 23.254.203[.]244 while deploying an infostealer, loader, Wi-Fi Updater component, and a more capable implant. The case shows how contact impersonation and brand-themed troubleshooting lures can give financially motivated DPRK operators hands-on access to macOS systems in gambling, crypto, and fintech-adjacent environments.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 23.254.203.244 2025-06-20 2026-04-03
HASH 73d26eb56e5a3426884733c104c3f625 2025-06-20 2025-10-28
HASH 1653d75d579872fadec1f22cf7fee3c0 2025-06-20 2025-10-28
HASH 036ca0a9d6a87e811f96f3aaadd8d05… 2025-06-20 2025-06-20
HASH 81612cab25c707a4c5d12bb21ff5f87… 2025-06-20 2025-06-20
HASH 6ffa82b33ec40477829e240458d6570… 2025-06-20 2025-06-20
HASH 5b6ce5e4ab8805884e497b53e57e05b… 2025-06-20 2025-06-20
HASH 4d101f0ca2bd81c23f0e68dbf34b3cd… 2025-06-20 2025-06-20
HASH ccf7f7678965105142f6878d7b1f1f1… 2025-06-20 2025-06-20
HASH 97ee87a342c9977383161185de934b2… 2025-06-20 2025-06-20
HASH c1793375aa046213293f367ad338f5d8 2025-06-20 2025-06-20
HASH 032e3e9a09f58a5b776c7374fc66d822 2025-06-20 2025-06-20
HASH 1269e7279b701777a660c7fa982f480… 2025-06-20 2025-06-20
EMAIL [email protected] 2025-06-20 2025-06-20
URL http://zoom-tech.us/zoom-meetin… 2025-06-20 2025-06-20
URL http://zoom-tech.us/fix/audio/ 2025-06-20 2025-06-20
URL https://zmwebsdk.com/zoom-data/… 2025-06-20 2025-06-20
URL https://ajayplamingop.com/ 2025-06-20 2025-06-20
URL https://ajayplamingo.com/ 2025-06-20 2025-06-20
URL http://zoom-tech.us/fix/audio-t… 2025-06-20 2025-06-20
DOMAIN meeting-zoom-witcam-tests-meet-… 2025-06-20 2025-06-20
DOMAIN boolnetwork.xyz 2025-06-20 2025-06-20
DOMAIN globiscapital.co 2025-06-20 2025-06-20
DOMAIN meet.picwe-team.com 2025-06-20 2025-06-20
DOMAIN alejandro.uefa-meeting.com 2025-06-20 2025-06-20
DOMAIN str8fire.businessmeet.xyz 2025-06-20 2025-06-20
DOMAIN openfort.xyz 2025-06-20 2025-06-20
DOMAIN meet.openfort-team.xyz 2025-06-20 2025-06-20
DOMAIN mzweb3.jp-zoom.com 2025-06-20 2025-06-20
DOMAIN luc.uefa-meeting.com 2025-06-20 2025-06-20
DOMAIN jp-zoom.com 2025-06-20 2025-06-20
DOMAIN fronterixbusiness.com 2025-06-20 2025-06-20
DOMAIN meet.globiscapital.co 2025-06-20 2025-06-20
DOMAIN synternetlab.com 2025-06-20 2025-06-20
DOMAIN zach.uefa-meeting.com 2025-06-20 2025-06-20
DOMAIN sammy.uefa-meeting.com 2025-06-20 2025-06-20
DOMAIN hwsrv-1275416.hostwindsdns.com 2025-06-20 2025-06-20
DOMAIN zooom.pages.dev 2025-06-20 2025-06-20
DOMAIN calystiabusiness.com 2025-06-20 2025-06-20
DOMAIN meet.synternetlab.com 2025-06-20 2025-06-20
DOMAIN zooommeeting.pages.dev 2025-06-20 2025-06-20
DOMAIN partners.boolnetwork.xyz 2025-06-20 2025-06-20
DOMAIN web3fund.io 2025-06-20 2025-06-20
DOMAIN zoom-tech.us 2025-06-20 2025-06-20
DOMAIN ajayplamingop.com 2025-06-20 2025-06-20
DOMAIN group.superstatefund.co 2025-06-20 2025-06-20
DOMAIN justbuiltprojects.com 2025-06-20 2025-06-20
DOMAIN meet.globiscapitals.com 2025-06-20 2025-06-20
DOMAIN zmwebsdk.com 2025-06-20 2025-06-20
DOMAIN openfort.businessmeet.xyz 2025-06-20 2025-06-20
DOMAIN twosigma-vc.com 2025-06-20 2025-06-20
DOMAIN hartmanmcapital.com 2025-06-20 2025-06-20
DOMAIN ae-zooom-hegne-meetingsfromf675… 2025-06-20 2025-06-20
DOMAIN capitalviabtc.com 2025-06-20 2025-06-20
DOMAIN tom.uefa-meeting.com 2025-06-20 2025-06-20
DOMAIN partner.hartmanmcapital.com 2025-06-20 2025-06-20
DOMAIN globiscapitals.com 2025-06-20 2025-06-20
DOMAIN superstatefund.co 2025-06-20 2025-06-20
DOMAIN api-zoom.com 2025-06-20 2025-06-20
DOMAIN meet.twosigma-vc.com 2025-06-20 2025-06-20
DOMAIN meet.superstatefund.co 2025-06-20 2025-06-20
DOMAIN republic.biz 2025-06-20 2025-06-20
DOMAIN openfort-team.xyz 2025-06-20 2025-06-20
DOMAIN dunamu.jp-zoom.com 2025-06-20 2025-06-20
DOMAIN uefa-meeting.com 2025-06-20 2025-06-20
DOMAIN meet.capitalviabtc.com 2025-06-20 2025-06-20
DOMAIN bizmeeting.org 2025-06-20 2025-06-20
DOMAIN baincapitalcrypto.zm-meeting.com 2025-06-20 2025-06-20
DOMAIN meetwithhealthyh2o.com 2025-06-20 2025-06-20
DOMAIN kourosh.uefa-meeting.com 2025-06-20 2025-06-20
DOMAIN ajayplamingo.com 2025-06-20 2025-06-20
DOMAIN zoom.personifyio.com 2025-06-20 2025-06-20
DOMAIN krakenmeetings.com 2025-06-20 2025-06-20
DOMAIN ignite.bizmeeting.org 2025-06-20 2025-06-20
DOMAIN zoomtomeet.pposbc.org 2025-06-20 2025-06-20
DOMAIN stage.bizmeet.org 2025-06-20 2025-06-20
DOMAIN riccardo.uefa-meeting.com 2025-06-20 2025-06-20
DOMAIN matias.uefa-meeting.com 2025-06-20 2025-06-20
DOMAIN xn--rxamia.com 2025-06-20 2025-06-20

Related Actors

Related Reports

« Back