Threat reportMalwareTL-2026-1719
BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency Credentials via ClickFix and AI Deepfake Social Engineering
BlueNoroff Fake Meeting Kit Captures Webcams, Disables (TL-2026-1719), also tracked as Fake Meeting Kit campaign, is a high-severity malware campaign, first published 2026-07-27. It is attributed to APT38 (North Korea) with high confidence, affects Microsoft Windows (10/11, all supported versions -- via social, maps to 41 MITRE ATT&CK techniques (T1005, T1027.004, T1036.005), and is covered by 9 detection rules and 34 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 41MITRE ATT&CK
- Actors
- 1APT38
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 34Indicators of compromise
Key facts for TL-2026-1719
- Threat ID
- TL-2026-1719
- Also known as
- Fake Meeting Kit campaign, BlueNoroff Zoom/Teams Phishing Kit, ClickFix Deepfake Meeting Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- APT38
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, blockchain, web3, fintech, venture capital, financial services
- Target regions
- united states of america, singapore, united kingdom, hong kong, North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 34
Malware and tooling in BlueNoroff Fake Meeting Kit Captures Webcams, Disables
Malware and tooling: CosmicDoor, NukeSped, SilentSiphon
How BlueNoroff Fake Meeting Kit Captures Webcams, Disables works
BlueNoroff (a financially motivated North Korean cluster subordinate to Lazarus Group) operates a self-sustaining phishing platform that impersonates Zoom, Microsoft Teams, and Google Meet, delivered through hijacked Telegram accounts of trusted crypto-industry contacts. The kit performs WebRTC webcam capture and AI-deepfake social engineering, EIP-6963/window.ethereum crypto-wallet fingerprinting, ClickFix clipboard-hijack payload delivery, and cross-platform (Windows PowerShell/VBScript, macOS AppleScript/Mach-O) malware that disables Microsoft Defender, hijacks Telegram sessions, and exfiltrates browser and Keychain credentials.
JUMPSEC recovered the active phishing-kit source code after its operators exposed JavaScript source maps on live infrastructure, and Arctic Wolf independently corroborated the campaign with over 100 identified victims across 20+ countries. The kit is a 'structured victim acquisition platform': operators hijack Telegram accounts belonging to trusted figures in the crypto/Web3 industry and send Calendly-style meeting invitations that redirect to typosquatted Zoom or Microsoft Teams domains (a Google Meet variant exists as unimplemented stub code). Victims are prompted to enter their name and grant webcam/microphone permissions; the page silently streams video via a mediasoup WebRTC relay to attacker infrastructure, and in the most advanced variant this feed is composited in near-real-time with ChatGPT/GPT-4o-generated synthetic faces layered onto body-motion footage captured from prior victims, producing a 'plausibly familiar' deepfake meeting host. Before any malware is delivered, the page fingerprints the victim's browser for cryptocurrency wallets via EIP-6963 provider discovery, legacy window.ethereum probing, and non-EVM (Solana) wallet enumeration, allowing operators to selectively push malware only to high-value, wallet-holding targets. Payload delivery uses the ClickFix technique: a staged 'microphone not working' error or fake 'Zoom SDK Update' prompt instructs the victim to paste and run a clipboard-injected command. On Windows this launches a lightweight, Base64+XOR (key 0x43) obfuscated PowerShell downloader that retrieves a VBScript implant (Symantec-identified Trojan.NukeSped, a Lazarus-associated backdoor family) or an alternate Trojan.SLoad loader; the script adds C:\Users to Microsoft Defender's exclusion path to disable AV, establishes persistence, performs WMI-based system reconnaissance, enumerates browser extensions across nine Chromium/Firefox-family browsers to match against known wallet extensions (e.g., MetaMask), and inspects browser profile directories for Telegram Web artifacts to hijack IndexedDB session data -- enabling account takeover and a self-propagating infection loop against the stolen contact's own network. A more advanced, independently observed Windows chain (Arctic Wolf) escalates to a fileless in-memory PowerShell C2 implant beaconing every 5 seconds to 83.136.208.246:6783/api/daemon, a C# browser-credential stealer that recovers the AES-256 master key via COM elevation (IElevator interface) to bypass Chrome 127+ app-bound encryption, and a UAC-bypass DLL using a COM elevation moniker. On macOS, a fake Teams/Zoom installer ("ZoomSDK.bin" in later, LLVM-obfuscated, integrated-stealer variants) deploys shell scripts and Mach-O binaries that abuse the macOS 'security' CLI to extract Keychain credentials, target Chrome-stored passwords, and exfiltrate data to a hardcoded Telegram bot channel named 'Aurora'. Infrastructure spans at least 11 initial C2 domains and more than 80 typosquatted lookalike domains registered since late 2025, hosted heavily on AS400897 (Petrosky Cloud LLC) and AS398256 (Ultrahost), with five distinct phishing-kit versions released between 2026-05-31 and 2026-07-14 showing active, rapid development. Victim telemetry shows ~80% of targets in crypto/blockchain finance, 45% holding CEO/founder titles, and operational activity clustering in Korean Standard Time business hours -- consistent with the group's SnatchCrypto operation lineage and its recently documented GhostCall/GhostHire campaigns (Kaspersky, Oct 2025), which used overlapping malware families (CosmicDoor, RealTimeTroy, RooTroy, SneakMain, DownTroy, ZoomClutch/TeamsClutch, SilentSiphon) and the same fake-videoconference social-engineering playbook.
MITRE ATT&CK techniques used in TL-2026-1719
Collection
T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data; T1123 Audio Capture; T1125 Video Capture
Defense Evasion
T1027.004 Compile After Delivery; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks; T1564.003 Hidden Window
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053.005 Scheduled Task; T1543.001 Launch Agent; T1547.001 Registry Run Keys / Startup Folder
Credential Access
T1056.001 Keylogging; T1539 Steal Web Session Cookie; T1552.001 Credentials In Files; T1555.001 Keychain; T1555.003 Credentials from Web Browsers
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1217 Browser Information Discovery; T1518.001 Security Software Discovery
Execution
T1059.001 PowerShell; T1059.002 AppleScript; T1059.004 Unix Shell; T1059.005 Visual Basic; T1204.004 Malicious Copy and Paste
Command and Control
T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1571 Non-Standard Port
Lateral Movement
Privilege Escalation
T1548.002 Bypass User Account Control
Initial Access
Resource Development
T1583.001 Domains; T1584.004 Server; T1586.002 Email Accounts; T1587.001 Malware
defense-impairment
Affected products and versions in BlueNoroff Fake Meeting Kit Captures Webcams, Disables
- Microsoft — Windows (10/11, all supported versions -- via social engineering, not an OS vulnerability)
Vulnerable versions: any Windows host where the victim executes the ClickFix PowerShell payload - Apple — macOS (via social engineering, not an OS vulnerability)
Vulnerable versions: any macOS host where the victim runs the fake Zoom/Teams installer or shell dropper - Various — Browser-based cryptocurrency wallet extensions (MetaMask and other EIP-6963/window.ethereum-compliant EVM wallets, non-EVM Solana wallets)
Vulnerable versions: any wallet extension installed in a compromised browser profile
Remediation for BlueNoroff Fake Meeting Kit Captures Webcams, Disables
Patches
- No vendor CVE/patch applies -- this is a social-engineering and malware delivery campaign, not a software vulnerability exploit
Immediate actions
- Block all identified typosquatted meeting domains and C2 IPs/ASNs (AS400897 Petrosky Cloud LLC, AS398256 Ultrahost) at the perimeter and DNS resolver
- Alert users to never grant camera/microphone access to unsolicited or last-minute Zoom/Teams/Google Meet links, especially from Telegram-originated invites
- Treat any 'paste this command to fix audio/video/SDK update' prompt during a video call as malicious (ClickFix) -- disable clipboard-to-Run/PowerShell execution via policy where feasible
- Audit Microsoft Defender exclusion paths for unauthorized entries (e.g., C:\Users) across endpoints
- Force re-authentication and session/device revocation for Telegram accounts of crypto-industry personnel; enable Telegram two-step verification
- Rotate/revoke browser-stored credentials and crypto-wallet seed phrases on any host suspected of compromise; assume MetaMask/browser-wallet extension state is burned
Workarounds
- Disable native clipboard paste-to-Run/PowerShell (Windows Group Policy: disable 'Win+R' clipboard execution or use AppLocker/WDAC constrained language mode)
- Restrict browser extension installation to an allow-list to reduce wallet-extension fingerprinting surface
- Require camera/microphone permission prompts to be manually reviewed per-domain rather than globally trusted for videoconferencing lookalike domains
Longer-term hardening
- Deploy EDR with PowerShell Script Block Logging and behavioral detection for Base64+XOR-obfuscated PowerShell, hidden-window PowerShell spawning, and runtime C# compilation via csc.exe/Add-Type
- Enforce application allow-listing / constrained language mode for PowerShell and disable VBScript execution (WSH) where not business-required
- Deploy macOS TCC/Endpoint Security monitoring for unauthorized 'security' CLI Keychain access and unsigned Mach-O execution from Downloads/temp paths
- Require hardware-backed authentication (FIDO2/passkeys) for cryptocurrency exchange and custody accounts instead of browser-stored credentials
- Provide executive/founder-level security awareness training specifically on deepfake video social engineering and AI-generated meeting hosts
Timeline of BlueNoroff Fake Meeting Kit Captures Webcams, Disables
- BlueNoroff's lineage traces to the $81M Bangladesh Bank SWIFT heist attempt, establishing the group's long-running financial-crime specialization within Lazarus Group.
- Kaspersky begins tracking the related GhostCall and GhostHire BlueNoroff campaigns targeting Web3 developers and executives across India, Turkey, Australia, and Europe.
- First infrastructure for the current fake-meeting-kit campaign observed, including registration of teams-live[.]us.
- Kaspersky (Securelist) publishes detailed GhostCall/GhostHire research at SAS 2025, documenting the malware families (CosmicDoor, RealTimeTroy, RooTroy, SneakMain, DownTroy, ZoomClutch/TeamsClutch, SilentSiphon) later found to overlap with this campaign.
- A primary tracked victim is compromised, with attacker persistence maintained for 66 days per Arctic Wolf telemetry.
- Telegram Bot API screenshot-exfiltration capability added to the malware, per Arctic Wolf infrastructure timeline.
- Researchers recover 950+ deepfake production media files and operator metadata from exposed infrastructure, revealing the ChatGPT/GPT-4o + Adobe Premiere Pro + FFmpeg deepfake production pipeline.
- First of five identified phishing-kit versions released, beginning a rapid iterative development cycle.
- Fifth and latest identified phishing-kit version released, reflecting active ongoing refinement as of report publication.
- JUMPSEC (via exposed JavaScript source maps) and GBHackers publicly disclose the fake meeting kit, its webcam-capture/Defender-disable/credential-theft chain, and initial IOCs.
Sources cited for BlueNoroff Fake Meeting Kit Captures Webcams, Disables
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
- BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector
- BlueNoroff's latest campaigns: GhostCall and GhostHire
- Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains
- Analysis Report of Lazarus Group's NukeSped Malware
- APT38, NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM, Group G0082
- BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes
Detection coverage for TL-2026-1719
As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1719 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1719
5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.