A recent investigation by researchers at Kaspersky has uncovered a phishing kit operated by the BlueNoroff group, a known North Korean threat actor. The phishing kit, designed to impersonate Zoom and Microsoft Teams, uses a technique called "profile injection" to gather sensitive information about potential victims. According to the researchers, the phishing kit creates a profile for each victim, which includes their name, email address, and other identifying details. The kit then uses this information to craft a personalized phishing email that appears to be from the compromised domain. The email is designed to trick the victim into revealing sensitive information, such as login credentials or private keys to cryptocurrency wallets.
The phishing kit also includes a "crypto wallet profile" feature, which allows the attackers to profile and track cryptocurrency wallets. This feature uses machine learning algorithms to identify and profile cryptocurrency wallets, making it more difficult for victims to detect the phishing attempt. The attackers can then use this information to deliver malware to the victim's cryptocurrency wallet, effectively stealing their cryptocurrency holdings.
The researchers at Kaspersky have noted that the phishing kit is highly sophisticated and is designed to evade detection by security software. The kit is also highly adaptable, allowing it to modify its tactics to evade detection by security software. The attackers are using this phishing kit to deliver malware to cryptocurrency wallets, which are increasingly popular among individuals and businesses.
The BlueNoroff group has been linked to several other high-profile cyber attacks in the past, including the WannaCry and NotPetya ransomware attacks. The group is known for its sophisticated tactics and its use of advanced technologies to evade detection by security software. The use of this phishing kit is just one example of the group's ongoing efforts to use social engineering tactics to steal sensitive information and deliver malware.