Fileless PowerShell Attack Linked To New BlueNoroff Cyber Campaign

Arctic Wolf researchers have uncovered a highly sophisticated cyber intrusion targeting a North American Web3 and cryptocurrency organization.

With high confidence, researchers attribute this ongoing global campaign to BlueNoroff, a financially motivated cybercrime subgroup of North Korea’s Lazarus Group.

The threat actors are using advanced social engineering, AI-generated deepfakes, and a unique fileless PowerShell attack to compromise high-value targets in the financial sector.

Deceptive Meetings and Deepfakes

The attack lifecycle begins with a carefully crafted social engineering approach. Threat actors impersonate reputable figures in the financial technology or legal sectors, reaching out to targets to schedule meetings.

They use spear-phishing techniques to deliver a manipulated Calendly calendar invitation that contains a typo-squatted Zoom or Microsoft Teams link. This malicious link is designed to look almost identical to a legitimate meeting URL.

DM screenshot (publicly shared online by a victim) showing a compromised Telegram account impersonating a previous victim and reaching out to a new target with a Calendly link (Source: arcticwolf)
DM screenshot (publicly shared online by a victim) showing a compromised Telegram account impersonating a previous victim and reaching out to a new target with a Calendly link (Source: arcticwolf)

Fileless Execution and Exploitation

As the fake meeting progresses, the victim realizes the audio is not working.

The malicious interface then displays a deceptive error message, claiming the victim’s video conferencing software development kit (SDK) is outdated and requires an immediate update. This triggers a “ClickFix” clipboard injection attack.

The victim is instructed to copy and paste what appears to be a harmless diagnostic command into the Windows Run dialog or a terminal. In reality, the victim is copying a malicious, fileless PowerShell script.

Heatmap of daily activity by hours of the day, mapped to Korean Standard Time (UTC+9) (Source: arcticwolf)
Heatmap of daily activity by hours of the day, mapped to Korean Standard Time (UTC+9) (Source: arcticwolf)

This initial PowerShell command downloads and executes an obfuscated secondary script from a command-and-control (C2) server.

The script establishes a persistent C2 implant in the system’s memory, allowing the attackers continuous access to the compromised machine. From there, BlueNoroff operators quickly deploy a series of post-exploitation modules.

HTML execution flow diagram showing the branching logic from initial page load through OS-conditional payload delivery (Source: arcticwolf)
HTML execution flow diagram showing the branching logic from initial page load through OS-conditional payload delivery (Source: arcticwolf)

The primary goal of these modules is to steal data and harvest credentials. The attackers deploy a script to steal Telegram Desktop sessions, allowing them to hijack the victim’s messaging account to approach new targets.

Shortly after, a sophisticated browser injection payload is launched. This payload injects AES-encrypted shellcode directly into running Chromium-based browsers, such as Chrome, Edge, and Brave.

The injected code bypasses browser security mechanisms to extract master encryption keys and decrypt stored credentials.

The stealers specifically target cryptocurrency wallet extensions, login data, and browser history.

In addition to credential theft, the malware captures high-quality screenshots of the victim’s desktop, either sending them via HTTP requests or exfiltrating them through a customized Telegram Bot API.

Arctic Wolf’s investigation identified over 100 individuals targeted by this campaign across 20 different countries. The heaviest concentration of victims is in the United States, followed by Singapore and the United Kingdom.

With nearly half of the targets holding CEO or founder titles, BlueNoroff’s operation highlights a precise, globally distributed effort to steal cryptocurrency through highly convincing, fileless attack chains.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories