Zoom & doom: BlueNoroff call opens the door
2025-06-20 • Field Effect •
https://fieldeffect.com/blog/zoom-doom-bluenoroff-call-opens-the-door
Field Effect investigated a compromise at a Canadian online gambling provider that it says may be associated with BlueNoroff, a financially motivated North Korean Lazarus subgroup. The victim joined a cryptocurrency-related Zoom meeting with an impersonated trusted contact and was prompted to run a fake Zoom audio repair script that hid malicious curl and zsh commands after thousands of blank lines. The macOS infection chain downloaded scripts from zoom-tech[.]us, collected the user's local password, used sudo, staged malware under Apple-like filenames, and installed LaunchDaemon persistence for privileged execution. Follow-on components communicated with infrastructure including ajayplamingo[.]com, ajayplamingop[.]com, and 23.254.203[.]244 while deploying an infostealer, loader, Wi-Fi Updater component, and a more capable implant. The case shows how contact impersonation and brand-themed troubleshooting lures can give financially motivated DPRK operators hands-on access to macOS systems in gambling, crypto, and fintech-adjacent environments.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 23.254.203.244 | 2025-06-20 | 2026-04-03 |
| HASH | 73d26eb56e5a3426884733c104c3f625 | 2025-06-20 | 2025-10-28 |
| HASH | 1653d75d579872fadec1f22cf7fee3c0 | 2025-06-20 | 2025-10-28 |
| HASH | 036ca0a9d6a87e811f96f3aaadd8d05… | 2025-06-20 | 2025-06-20 |
| HASH | 81612cab25c707a4c5d12bb21ff5f87… | 2025-06-20 | 2025-06-20 |
| HASH | 6ffa82b33ec40477829e240458d6570… | 2025-06-20 | 2025-06-20 |
| HASH | 5b6ce5e4ab8805884e497b53e57e05b… | 2025-06-20 | 2025-06-20 |
| HASH | 4d101f0ca2bd81c23f0e68dbf34b3cd… | 2025-06-20 | 2025-06-20 |
| HASH | ccf7f7678965105142f6878d7b1f1f1… | 2025-06-20 | 2025-06-20 |
| HASH | 97ee87a342c9977383161185de934b2… | 2025-06-20 | 2025-06-20 |
| HASH | c1793375aa046213293f367ad338f5d8 | 2025-06-20 | 2025-06-20 |
| HASH | 032e3e9a09f58a5b776c7374fc66d822 | 2025-06-20 | 2025-06-20 |
| HASH | 1269e7279b701777a660c7fa982f480… | 2025-06-20 | 2025-06-20 |
| [email protected] | 2025-06-20 | 2025-06-20 | |
| URL | http://zoom-tech.us/zoom-meetin… | 2025-06-20 | 2025-06-20 |
| URL | http://zoom-tech.us/fix/audio/ | 2025-06-20 | 2025-06-20 |
| URL | https://zmwebsdk.com/zoom-data/… | 2025-06-20 | 2025-06-20 |
| URL | https://ajayplamingop.com/ | 2025-06-20 | 2025-06-20 |
| URL | https://ajayplamingo.com/ | 2025-06-20 | 2025-06-20 |
| URL | http://zoom-tech.us/fix/audio-t… | 2025-06-20 | 2025-06-20 |
| DOMAIN | meeting-zoom-witcam-tests-meet-… | 2025-06-20 | 2025-06-20 |
| DOMAIN | boolnetwork.xyz | 2025-06-20 | 2025-06-20 |
| DOMAIN | globiscapital.co | 2025-06-20 | 2025-06-20 |
| DOMAIN | meet.picwe-team.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | alejandro.uefa-meeting.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | str8fire.businessmeet.xyz | 2025-06-20 | 2025-06-20 |
| DOMAIN | openfort.xyz | 2025-06-20 | 2025-06-20 |
| DOMAIN | meet.openfort-team.xyz | 2025-06-20 | 2025-06-20 |
| DOMAIN | mzweb3.jp-zoom.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | luc.uefa-meeting.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | jp-zoom.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | fronterixbusiness.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | meet.globiscapital.co | 2025-06-20 | 2025-06-20 |
| DOMAIN | synternetlab.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | zach.uefa-meeting.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | sammy.uefa-meeting.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | hwsrv-1275416.hostwindsdns.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | zooom.pages.dev | 2025-06-20 | 2025-06-20 |
| DOMAIN | calystiabusiness.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | meet.synternetlab.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | zooommeeting.pages.dev | 2025-06-20 | 2025-06-20 |
| DOMAIN | partners.boolnetwork.xyz | 2025-06-20 | 2025-06-20 |
| DOMAIN | web3fund.io | 2025-06-20 | 2025-06-20 |
| DOMAIN | zoom-tech.us | 2025-06-20 | 2025-06-20 |
| DOMAIN | ajayplamingop.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | group.superstatefund.co | 2025-06-20 | 2025-06-20 |
| DOMAIN | justbuiltprojects.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | meet.globiscapitals.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | zmwebsdk.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | openfort.businessmeet.xyz | 2025-06-20 | 2025-06-20 |
| DOMAIN | twosigma-vc.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | hartmanmcapital.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | ae-zooom-hegne-meetingsfromf675… | 2025-06-20 | 2025-06-20 |
| DOMAIN | capitalviabtc.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | tom.uefa-meeting.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | partner.hartmanmcapital.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | globiscapitals.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | superstatefund.co | 2025-06-20 | 2025-06-20 |
| DOMAIN | api-zoom.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | meet.twosigma-vc.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | meet.superstatefund.co | 2025-06-20 | 2025-06-20 |
| DOMAIN | republic.biz | 2025-06-20 | 2025-06-20 |
| DOMAIN | openfort-team.xyz | 2025-06-20 | 2025-06-20 |
| DOMAIN | dunamu.jp-zoom.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | uefa-meeting.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | meet.capitalviabtc.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | bizmeeting.org | 2025-06-20 | 2025-06-20 |
| DOMAIN | baincapitalcrypto.zm-meeting.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | meetwithhealthyh2o.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | kourosh.uefa-meeting.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | ajayplamingo.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | zoom.personifyio.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | krakenmeetings.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | ignite.bizmeeting.org | 2025-06-20 | 2025-06-20 |
| DOMAIN | zoomtomeet.pposbc.org | 2025-06-20 | 2025-06-20 |
| DOMAIN | stage.bizmeet.org | 2025-06-20 | 2025-06-20 |
| DOMAIN | riccardo.uefa-meeting.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | matias.uefa-meeting.com | 2025-06-20 | 2025-06-20 |
| DOMAIN | xn--rxamia.com | 2025-06-20 | 2025-06-20 |