{"id":4828,"date":"2025-06-23T10:03:38","date_gmt":"2025-06-23T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/23\/bluenoroff-hackers-weaponize-zoom-app-to-attack-system-using-infostealer-malware\/"},"modified":"2025-06-23T10:03:38","modified_gmt":"2025-06-23T10:03:38","slug":"bluenoroff-hackers-weaponize-zoom-app-to-attack-system-using-infostealer-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/23\/bluenoroff-hackers-weaponize-zoom-app-to-attack-system-using-infostealer-malware\/","title":{"rendered":"BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware"},"content":{"rendered":"<p>    BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated social engineering campaign leveraging the trusted Zoom platform has emerged as the latest weapon in the arsenal of North Korean state-sponsored hackers.<\/p>\n<p>The BlueNoroff group, a financially motivated subgroup of the notorious Lazarus Group, has been orchestrating targeted attacks against cryptocurrency and financial sector organizations through convincingly spoofed Zoom-related infrastructure and impersonation tactics.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/new-phishing-campaign-attacking-investors\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaign<\/a>, which has been active since at least March 2025, represents a significant evolution in cybercriminal tradecraft, exploiting the ubiquity of video conferencing platforms in modern business operations.<\/p>\n<p>Threat actors have successfully compromised victims by impersonating known business contacts during scheduled Zoom meetings, then manipulating targets into executing malicious scripts disguised as legitimate audio repair tools.<\/p>\n<p>This approach capitalizes on the operational urgency and routine nature of technical troubleshooting in remote work environments.<\/p>\n<p>Field Effect analysts <a href=\"https:\/\/fieldeffect.com\/blog\/zoom-doom-bluenoroff-call-opens-the-door\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> a distinct incident involving a Canadian online gambling provider on May 28, 2025, where the threat actor employed advanced social engineering techniques to gain initial access to the victim\u2019s system.<\/p>\n<p>The attack demonstrates the group\u2019s operational maturity and their continued focus on cryptocurrency-related targets, aligning with BlueNoroff\u2019s historical mission to generate revenue for the North Korean regime through cybercrime activities.<\/p>\n<p>The financial and operational impact of these attacks extends beyond immediate data theft, as the malware specifically targets <a href=\"https:\/\/cybersecuritynews.com\/cryptocore-cryptocurrency-scam-draining-wallets\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency wallet<\/a> extensions, browser credentials, and authentication keys.<\/p>\n<p>Organizations in the gaming, entertainment, and fintech sectors across North America, Europe, and Asia-Pacific regions have been identified as primary targets, with the campaign\u2019s scope indicating a coordinated effort to compromise high-value cryptocurrency assets and sensitive financial data.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Sophisticated Infection Mechanism and Multi-Stage Deployment<\/strong><\/h2>\n<p>The attack chain begins with a meticulously crafted AppleScript that initially appears to perform legitimate Zoom SDK updates and maintenance tasks.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi1i9RiYZDqL5EEApRF5oTMrTM0iGkpkCDYSPnzkazioyjFtSD_GTOKkC_heU8YzzNEXwQAW8YIx8RwyIL-JSVA7rlpqgFXskSz7HyzO1gdcXE1Ybf9PgImU-3NjkPOnb1X5rC3aFkHNNfqEVdriU_l1lPvfdc8raO5jl0uoAnFAv2cqhrWrvIh8v4v0cU\/s16000\/Zoom%2520SDK%2520Update%2520script%2520%28Source%2520-%2520Field%2520Effect%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Zoom SDK Update script (Source \u2013 Field Effect)<\/figcaption><\/figure>\n<\/div>\n<p>However, analysis of the malicious script reveals approximately 10,000 blank lines designed to obscure the true payload.<\/p>\n<p>The concealed commands execute on lines 10,017 and 10,018, where a curl request downloads and executes the primary <a href=\"https:\/\/cybersecuritynews.com\/raccoon-infostealer-admin-arrested\/\" target=\"_blank\" rel=\"noreferrer noopener\">infostealer<\/a> component from the fraudulent domain zoom-tech[.]us.<\/p>\n<p>The malware establishes persistence through multiple mechanisms, including LaunchDaemon configurations that ensure execution at boot time with <a href=\"https:\/\/cybersecuritynews.com\/windows-active-directory-domain-vulnerability-let-attackers-escalate-privileges\/\" target=\"_blank\" rel=\"noreferrer noopener\">administrator privileges<\/a>.<\/p>\n<p>The infection process involves downloading additional payloads from compromised infrastructure, including components masquerading as legitimate system utilities like \u201cicloud_helper\u201d and \u201cWi-Fi Updater.\u201d<\/p>\n<p>These components employ sophisticated anti-forensics techniques, automatically removing temporary files and staging directories to minimize their forensic footprint while maintaining operational capabilities for data exfiltration and command execution.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><code>Are you from SOC\/DFIR Teams! - Interact with malware in the sandbox and find related IOCs. -\u00a0<a href=\"https:\/\/any.run\/demo\/?utm_source=csn_jun&amp;utm_medium=article&amp;utm_campaign=threat_hunting_tips&amp;utm_term=190625&amp;utm_content=linktodemo\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request 14-day free trial<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/bluenoroff-hackers-weaponize-zoom-app\/\">BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/bluenoroff-hackers-weaponize-zoom-app\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware A sophisticated social engineering campaign leveraging the trusted Zoom platform has emerged as the latest weapon in the arsenal of North Korean state-sponsored hackers. The BlueNoroff group, a financially motivated subgroup of the notorious Lazarus Group, has been orchestrating targeted attacks against cryptocurrency and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-4828","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4828"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4828"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4828\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4828"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4828"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4828"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}