# BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency Credentials via ClickFix and AI Deepfake Social Engineering

> BlueNoroff (a financially motivated North Korean cluster subordinate to Lazarus Group) operates a self-sustaining phishing platform that impersonates Zoom, Microsoft Teams, and Google Meet, delivered through hijacked Telegram accounts of trusted crypto-industry contacts. The kit performs WebRTC webcam capture and AI-deepfake social engineering, EIP-6963/window.ethereum crypto-wallet fingerprinting, ClickFix clipboard-hijack payload delivery, and cross-platform (Windows PowerShell/VBScript, macOS AppleScript/Mach-O) malware that disables Microsoft Defender, hijacks Telegram sessions, and exfiltrates browser and Keychain credentials.

- **Published:** 2026-07-27T00:00:00Z
- **Last reviewed:** 2026-07-27T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1719
- **ID:** TL-2026-1719
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** APT38 (North Korea)
- **Detections:** 9 · **IOCs:** 34 (full data via the Threadlinqs MCP server — Purple tier)

## Description

JUMPSEC recovered the active phishing-kit source code after its operators exposed JavaScript source maps on live infrastructure, and Arctic Wolf independently corroborated the campaign with over 100 identified victims across 20+ countries. The kit is a 'structured victim acquisition platform': operators hijack Telegram accounts belonging to trusted figures in the crypto/Web3 industry and send Calendly-style meeting invitations that redirect to typosquatted Zoom or Microsoft Teams domains (a Google Meet variant exists as unimplemented stub code). Victims are prompted to enter their name and grant webcam/microphone permissions; the page silently streams video via a mediasoup WebRTC relay to attacker infrastructure, and in the most advanced variant this feed is composited in near-real-time with ChatGPT/GPT-4o-generated synthetic faces layered onto body-motion footage captured from prior victims, producing a 'plausibly familiar' deepfake meeting host. Before any malware is delivered, the page fingerprints the victim's browser for cryptocurrency wallets via EIP-6963 provider discovery, legacy window.ethereum probing, and non-EVM (Solana) wallet enumeration, allowing operators to selectively push malware only to high-value, wallet-holding targets. Payload delivery uses the ClickFix technique: a staged 'microphone not working' error or fake 'Zoom SDK Update' prompt instructs the victim to paste and run a clipboard-injected command. On Windows this launches a lightweight, Base64+XOR (key 0x43) obfuscated PowerShell downloader that retrieves a VBScript implant (Symantec-identified Trojan.NukeSped, a Lazarus-associated backdoor family) or an alternate Trojan.SLoad loader; the script adds C:\Users to Microsoft Defender's exclusion path to disable AV, establishes persistence, performs WMI-based system reconnaissance, enumerates browser extensions across nine Chromium/Firefox-family browsers to match against known wallet extensions (e.g., MetaMask), and inspects browser profile directories for Telegram Web artifacts to hijack IndexedDB session data -- enabling account takeover and a self-propagating infection loop against the stolen contact's own network. A more advanced, independently observed Windows chain (Arctic Wolf) escalates to a fileless in-memory PowerShell C2 implant beaconing every 5 seconds to 83.136.208.246:6783/api/daemon, a C# browser-credential stealer that recovers the AES-256 master key via COM elevation (IElevator interface) to bypass Chrome 127+ app-bound encryption, and a UAC-bypass DLL using a COM elevation moniker. On macOS, a fake Teams/Zoom installer ("ZoomSDK.bin" in later, LLVM-obfuscated, integrated-stealer variants) deploys shell scripts and Mach-O binaries that abuse the macOS 'security' CLI to extract Keychain credentials, target Chrome-stored passwords, and exfiltrate data to a hardcoded Telegram bot channel named 'Aurora'. Infrastructure spans at least 11 initial C2 domains and more than 80 typosquatted lookalike domains registered since late 2025, hosted heavily on AS400897 (Petrosky Cloud LLC) and AS398256 (Ultrahost), with five distinct phishing-kit versions released between 2026-05-31 and 2026-07-14 showing active, rapid development. Victim telemetry shows ~80% of targets in crypto/blockchain finance, 45% holding CEO/founder titles, and operational activity clustering in Korean Standard Time business hours -- consistent with the group's SnatchCrypto operation lineage and its recently documented GhostCall/GhostHire campaigns (Kaspersky, Oct 2025), which used overlapping malware families (CosmicDoor, RealTimeTroy, RooTroy, SneakMain, DownTroy, ZoomClutch/TeamsClutch, SilentSiphon) and the same fake-videoconference social-engineering playbook.

## MITRE ATT&CK

- T1583.001 Domains
- T1584.004 Server
- T1586.002 Email Accounts
- T1587.001 Malware
- T1566.002 Spearphishing Link
- T1204.004 Malicious Copy and Paste
- T1059.001 PowerShell
- T1059.005 Visual Basic
- T1059.002 AppleScript
- T1059.004 Unix Shell
- T1547.001 Registry Run Keys / Startup Folder
- T1543.001 Launch Agent
- T1053.005 Scheduled Task
- T1548.002 Bypass User Account Control
- T1685 Disable or Modify Tools
- T1027.004 Compile After Delivery
- T1036.005 Match Legitimate Resource Name or Location
- T1055 Process Injection
- T1564.003 Hidden Window
- T1497.001 System Checks
- T1140 Deobfuscate/Decode Files or Information
- T1555.003 Credentials from Web Browsers
- T1555.001 Keychain
- T1539 Steal Web Session Cookie
- T1552.001 Credentials In Files
- T1056.001 Keylogging
- T1518.001 Security Software Discovery
- T1082 System Information Discovery
- T1057 Process Discovery
- T1217 Browser Information Discovery
- T1534 Internal Spearphishing
- T1125 Video Capture
- T1123 Audio Capture
- T1113 Screen Capture
- T1115 Clipboard Data
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1571 Non-Standard Port
- T1102.002 Bidirectional Communication
- T1041 Exfiltration Over C2 Channel

## Sources

- [BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials](https://gbhackers.com/bluenoroff-fake-meeting-kit/)
- [BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery](https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html)
- [BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector](https://arcticwolf.com/resources/blog-uk/bluenoroff-uses-clickfix-fileless-powershell-ai-generated-fake-zoom-meetings-to-target-web3-sector/)
- [BlueNoroff's latest campaigns: GhostCall and GhostHire](https://securelist.com/bluenoroff-apt-campaigns-ghostcall-and-ghosthire/117842/)
- [Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains](https://thehackernews.com/2025/10/researchers-expose-ghostcall-and.html)
- [Analysis Report of Lazarus Group's NukeSped Malware](https://asec.ahnlab.com/en/28597/)
- [APT38, NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM, Group G0082](https://attack.mitre.org/groups/G0082/)
- [BlueNoroff targets crypto users with fake Zoom and Teams meetings, compromising victims in under five minutes](https://cryptobriefing.com/bluenoroff-fake-zoom-teams-crypto-theft/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1719
