BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency Credentials via ClickFix and AI Deepfake Social Engineering — Threadlinqs Intelligence
As of 2026-07-27, BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency Credentials via ClickFix and AI Deepfake Social Engineering is a high-severity malware threat attributed to APT38 (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1719 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: APT38 · North Korea (DPRK) · FINANCIAL
BlueNoroff (a financially motivated North Korean cluster subordinate to Lazarus Group) operates a self-sustaining phishing platform that impersonates Zoom, Microsoft Teams, and Google Meet, delivered
JUMPSEC recovered the active phishing-kit source code after its operators exposed JavaScript source maps on live infrastructure, and Arctic Wolf independently corroborated the campaign with over 100 identified victims across 20+ countries. The kit is a 'structured victim acquisition platform': operators hijack Telegram accounts belonging to trusted figures in the crypto/Web3 industry and send Calendly-style meeting invitations that redirect to typosquatted Zoom or Microsoft Teams domains (a Google Meet variant exists as unimplemented stub code). Victims are prompted to enter their name and grant webcam/microphone permissions; the page silently streams video via a mediasoup WebRTC relay to attacker infrastructure, and in the most advanced variant this feed is composited in near-real-time with ChatGPT/GPT-4o-generated synthetic faces layered onto body-motion footage captured from prior victims, producing a 'plausibly familiar' deepfake meeting host. Before any malware is delivered, the page fingerprints the victim's browser for cryptocurrency wallets via EIP-6963 provider discovery, legacy window.ethereum probing, and non-EVM (Solana) wallet enumeration, allowing operators to selectively push malware only to high-value, wallet-holding targets. Payload delivery uses the ClickFix technique: a staged 'microphone not working' error or fake 'Zoom SDK Update' prompt instructs the victim to paste and run a clipboard-injected command. On Windows this launches a lightweight, Base64+XOR (key 0x43) obfuscated PowerShell downloader that retrieves a VBScript implant (Symantec-identified Trojan.NukeSped, a Lazarus-associated backdoor family) or an alternate Trojan.SLoad loader; the script adds C:\Users to Microsoft Defender's exclusion path to disable AV, establishes persistence, performs WMI-based system reconnaissance, enumerates browser extensions across nine Chromium/Firefox-family browsers to match against known wallet extensions (e.g., MetaMask), and inspects browser profile directories for Telegram Web artifacts to hijack IndexedDB session data -- enabling account takeover and a self-propagating infection loop against the stolen contact's own network. A more advanced, independently observed Windows chain (Arctic Wolf) escalates to a fileless in-memory PowerShell C2 implant beaconing every 5 seconds to 83.136.208.246:6783/api/daemon, a C# browser-credential stealer that recovers the AES-256 master key via COM elevation (IElevator interface) to bypass Chrome 127+ app-bound encryption, and a UAC-bypass DLL using a COM elevation moniker. On macOS, a fake Teams/Zoom installer ("ZoomSDK.bin" in later, LLVM-obfuscated, integrated-stealer variants) deploys shell scripts and Mach-O binaries that abuse the macOS 'security' CLI to extract Keychain credentials, target Chrome-stored passwords, and exfiltrate data to a hardcoded Telegram bot channel named 'Aurora'. Infrastructure spans at least 11 initial C2 domains and more than 80 typosquatted lookalike domains registered since late 2025, hosted heavily on AS400897 (Petrosky Cloud LLC) and AS398256 (Ultrahost), with five distinct phishing-kit versions released between 2026-05-31 and 2026-07-14 showing active, rapid development. Victim telemetry shows ~80% of targets in crypto/blockchain finance, 45% holding CEO/founder titles, and operational activity clustering in Korean Standard Time business hours -- consistent with the group's SnatchCrypto operation lineage and its recently documented GhostCall/GhostHire campaigns (Kaspersky, Oct 2025), which used overlapping malware families (CosmicDoor, RealTimeTroy, RooTroy, SneakMain, DownTroy, ZoomClutch/TeamsClutch, SilentSiphon) and the same fake-videoconference social-engineering playbook.
Target sectors: cryptocurrency, blockchain, web3, fintech, venture capital, financial services
Target regions: united states of america, singapore, united kingdom, hong kong, North America, Europe, Asia-Pacific
References
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
- BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector
- BlueNoroff's latest campaigns: GhostCall and GhostHire
- Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains
- Analysis Report of Lazarus Group's NukeSped Malware
- APT38, NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM, Group G0082
- BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1584.004, T1586.002, T1587.001, T1566.002, T1204.004, T1059.001, T1059.005, T1059.002, T1059.004