BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls — Threadlinqs Intelligence
As of 2026-07-27, BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls is a high-severity malware threat attributed to APT38 (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 39 indicators of compromise.
Threat ID: TL-2026-1720 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: APT38 · North Korea · FINANCIAL
BlueNoroff (DPRK, Lazarus-linked) hijacks compromised Telegram accounts of trusted industry contacts to lure Web3/crypto executives into fake Zoom/Teams meetings, sustains the deception with a
Between at least 2026-04-22 and 2026-07-15, BlueNoroff (a financially-motivated Lazarus Group sub-cluster also tracked as APT38/TA444/Sapphire Sleet/Stardust Chollima) ran a self-propagating social-engineering pipeline against cryptocurrency and Web3 executives. Compromised Telegram accounts belonging to real, trusted industry contacts are used to send fake Zoom or Microsoft Teams meeting invitations. Victims are redirected to attacker-owned typosquat domains (e.g. us.zoom.06webin.us, zoom.05ukweb.uk, microsoft-workspace.live) hosting a fake meeting client that silently captures webcam feed via WebRTC/mediasoup and fingerprints the browser for cryptocurrency wallets (EIP-6963 and legacy window.ethereum probing for MetaMask, plus Solana wallet detection) before the operator ever appears. Once a high-value wallet profile is confirmed, an operator joins the call and plays a pre-produced deepfake video composited from AI-generated headshots and real body motion harvested from prior victims' captured footage, sustaining the impression of a live human presence. A scripted social-engineering sequence (an on-time "can you hear me" opener, a false claim the meeting SDK is out of date, and an auto-advancing fake update progress bar) culminates in a ClickFix clipboard-hijack box: when the victim copies the displayed "fix" command, the clipboard contents are silently substituted with a malicious command. On Windows this launches a self-deleting PowerShell loader that downloads and double-executes a VBScript C2 implant (classified by VirusTotal as Trojan.NukeSped and Trojan.SLoad, both associated with the Lazarus Group), which disables Windows Defender via an Add-MpPreference exclusion, profiles the host (WMI domain/username, OS/CPU/timezone/network adapters, running processes, installed browser extensions, and Telegram IndexedDB usage across ten browser variants), and beacons recon data and execution status to attacker C2 before staging further PE payloads. On macOS the ClickFix command instead drops a shell script that self-deletes, displays a decoy ZoomApp.app/TeamsApp.app/SystemApp.app installer via osascript to keep the victim occupied, bypasses Gatekeeper (xattr -rc plus ad-hoc codesign), and executes a Mach-O ARM64 dropper (four observed builds, April-July 2026, progressively obfuscated with LLVM control-flow flattening) that version-gates on macOS >= 26.4 before running a Chrome-keychain stealer (`security find-generic-password -wa "Chrome"`) and exfiltrating the base64-encoded master key via a hardcoded Telegram bot (observed rotating from an "Aurora" channel in May-June to a "Login PWD" bot in July). Infected machines with an active Telegram session feed a self-propagation loop: the malware harvests the session, and the compromised account is used to approach the original victim's own trusted contacts, sustaining a continuous acquisition pipeline. All identified infrastructure (21 high-confidence domains, 9 IPs) sits behind Cloudzy/RouterHosting LLC (AS14956), a hosting provider previously documented supporting DPRK and Iranian APT infrastructure, and shares an identical XAMPP/Apache/PHP server fingerprint and AES-GCM-256 execute-link encryption scheme across all deployments. JUMPSEC discovered the campaign via exposed JavaScript source maps left on live attacker infrastructure and published findings on 2026-07-24; the technique, infrastructure pattern, and deepfake-meeting tradecraft closely mirror BlueNoroff's Arctic Wolf-documented April 2026 Web3 intrusion and Kaspersky's October 2025 GhostCall/GhostHire reporting, corroborating high-confidence attribution to the same actor and its ongoing SnatchCrypto operation.
Target sectors: cryptocurrency, web3, blockchain, financial services, venture capital
Target regions: Global
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 39 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
7 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1586, T1583, T1584, T1585, T1199, T1078, T1566, T1204, T1059, T1685