Threat reportMalwareTL-2026-1720

BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls

highACTIVE

BlueNoroff Hijacks Trusted Telegram Accounts to Deliver (TL-2026-1720), also tracked as DPRK BlueNoroff ClickFix Kit, is a high-severity malware campaign, first published 2026-07-27. It is attributed to APT38 (North Korea) with high confidence, affects Zoom Video Communications Zoom (brand impersonated via typosquat lure, maps to 29 MITRE ATT&CK techniques (T1016, T1027, T1041), and is covered by 9 detection rules and 39 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
1APT38
Detection rules
9SPL · KQL · Sigma
IOCs
39Indicators of compromise

Key facts for TL-2026-1720

Threat ID
TL-2026-1720
Also known as
DPRK BlueNoroff ClickFix Kit, GhostCall-adjacent Telegram-hijack campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
APT38
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
cryptocurrency, web3, blockchain, financial services, venture capital
Target regions
Global
Detection rules
9
Indicators of compromise
39

Malware and tooling in BlueNoroff Hijacks Trusted Telegram Accounts to Deliver

Malware and tooling: Trojan.NukeSped, Trojan.SLoad, ClickFix

How BlueNoroff Hijacks Trusted Telegram Accounts to Deliver works

BlueNoroff (DPRK, Lazarus-linked) hijacks compromised Telegram accounts of trusted industry contacts to lure Web3/crypto executives into fake Zoom/Teams meetings, sustains the deception with a pre-produced AI-generated deepfake operator video, then deploys a ClickFix clipboard-hijack chain delivering Trojan.NukeSped/Trojan.SLoad (Windows) and Mach-O droppers (macOS) to steal cryptocurrency wallet and Chrome-keychain credentials.

Between at least 2026-04-22 and 2026-07-15, BlueNoroff (a financially-motivated Lazarus Group sub-cluster also tracked as APT38/TA444/Sapphire Sleet/Stardust Chollima) ran a self-propagating social-engineering pipeline against cryptocurrency and Web3 executives. Compromised Telegram accounts belonging to real, trusted industry contacts are used to send fake Zoom or Microsoft Teams meeting invitations. Victims are redirected to attacker-owned typosquat domains (e.g. us.zoom.06webin.us, zoom.05ukweb.uk, microsoft-workspace.live) hosting a fake meeting client that silently captures webcam feed via WebRTC/mediasoup and fingerprints the browser for cryptocurrency wallets (EIP-6963 and legacy window.ethereum probing for MetaMask, plus Solana wallet detection) before the operator ever appears. Once a high-value wallet profile is confirmed, an operator joins the call and plays a pre-produced deepfake video composited from AI-generated headshots and real body motion harvested from prior victims' captured footage, sustaining the impression of a live human presence. A scripted social-engineering sequence (an on-time "can you hear me" opener, a false claim the meeting SDK is out of date, and an auto-advancing fake update progress bar) culminates in a ClickFix clipboard-hijack box: when the victim copies the displayed "fix" command, the clipboard contents are silently substituted with a malicious command. On Windows this launches a self-deleting PowerShell loader that downloads and double-executes a VBScript C2 implant (classified by VirusTotal as Trojan.NukeSped and Trojan.SLoad, both associated with the Lazarus Group), which disables Windows Defender via an Add-MpPreference exclusion, profiles the host (WMI domain/username, OS/CPU/timezone/network adapters, running processes, installed browser extensions, and Telegram IndexedDB usage across ten browser variants), and beacons recon data and execution status to attacker C2 before staging further PE payloads. On macOS the ClickFix command instead drops a shell script that self-deletes, displays a decoy ZoomApp.app/TeamsApp.app/SystemApp.app installer via osascript to keep the victim occupied, bypasses Gatekeeper (xattr -rc plus ad-hoc codesign), and executes a Mach-O ARM64 dropper (four observed builds, April-July 2026, progressively obfuscated with LLVM control-flow flattening) that version-gates on macOS >= 26.4 before running a Chrome-keychain stealer (`security find-generic-password -wa "Chrome"`) and exfiltrating the base64-encoded master key via a hardcoded Telegram bot (observed rotating from an "Aurora" channel in May-June to a "Login PWD" bot in July). Infected machines with an active Telegram session feed a self-propagation loop: the malware harvests the session, and the compromised account is used to approach the original victim's own trusted contacts, sustaining a continuous acquisition pipeline. All identified infrastructure (21 high-confidence domains, 9 IPs) sits behind Cloudzy/RouterHosting LLC (AS14956), a hosting provider previously documented supporting DPRK and Iranian APT infrastructure, and shares an identical XAMPP/Apache/PHP server fingerprint and AES-GCM-256 execute-link encryption scheme across all deployments. JUMPSEC discovered the campaign via exposed JavaScript source maps left on live attacker infrastructure and published findings on 2026-07-24; the technique, infrastructure pattern, and deepfake-meeting tradecraft closely mirror BlueNoroff's Arctic Wolf-documented April 2026 Web3 intrusion and Kaspersky's October 2025 GhostCall/GhostHire reporting, corroborating high-confidence attribution to the same actor and its ongoing SnatchCrypto operation.

MITRE ATT&CK techniques used in TL-2026-1720

Discovery

T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1518 Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1480 Execution Guardrails

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Collection

T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data; T1125 Video Capture

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1573 Encrypted Channel

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing

Credential Access

T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts

Affected products and versions in BlueNoroff Hijacks Trusted Telegram Accounts to Deliver

  • Zoom Video Communications — Zoom (brand impersonated via typosquat lure domains)
    Vulnerable versions: N/A - social engineering / brand impersonation, no product vulnerability
  • Microsoft — Microsoft Teams (brand impersonated via typosquat lure domains)
    Vulnerable versions: N/A - social engineering / brand impersonation, no product vulnerability
  • Microsoft — Windows (PowerShell + Windows Script Host execution environment abused for loader and implant stages)
    Vulnerable versions: All supported Windows versions with PowerShell and WSH (.vbs) enabled
  • Apple — macOS (Mach-O dropper and Chrome-keychain stealer, version-gated to execute only on newer releases)
    Vulnerable versions: macOS 26.4 and later (stealer execution gate `kern.osproductversion`)
  • Google — Chrome (credentials stored in the macOS Keychain targeted via the `security` CLI)
    Vulnerable versions: All versions storing generic passwords in macOS Keychain

Remediation for BlueNoroff Hijacks Trusted Telegram Accounts to Deliver

Immediate actions

  • Block all listed C2/lure domains and IPs (see IOCs) at DNS resolver, perimeter firewall, and web proxy layers
  • Alert on and isolate any Windows/macOS host observed resolving edensun.xyz or any Cloudzy/RouterHosting LLC (AS14956) IP in this record
  • Hunt for oklnkae.vbs / NltOci4.vbs in %TEMP%, ZoomApp.app/TeamsApp.app/SystemApp.app decoy installers, and Add-MpPreference Windows Defender exclusions targeting C:\Users
  • Force-rotate credentials and Chrome-stored passwords for any employee who joined an unscheduled Zoom/Teams call originating from a Telegram contact in the campaign window
  • Revoke and re-issue active Telegram sessions org-wide for crypto/Web3 staff; enforce Telegram two-step verification

Workarounds

  • Where feasible, restrict browser clipboard-paste execution/auto-run behavior for unmanaged or unrecognized meeting-platform sessions
  • Permit Zoom/Teams client and SDK installation only via managed software deployment; block ad-hoc third-party SDK installers

Longer-term hardening

  • Deploy EDR behavioral detection for clipboard-write hijacking (ClickFix) and for wscript.exe/osascript spawning outbound network connections
  • Require out-of-band (phone/in-person) verification for meeting invites from previously-trusted contacts whose behavior or wording suddenly changes
  • Restrict or closely monitor PowerShell, VBScript (WSH), and AppleScript execution on endpoints used by staff with cryptocurrency wallet access
  • Monitor for ad-hoc codesign + xattr -rc invocations against newly downloaded macOS binaries as a Gatekeeper-bypass indicator
  • Run recurring ClickFix/deepfake-meeting social-engineering awareness training for finance, executive, and Web3-facing staff

Timeline of BlueNoroff Hijacks Trusted Telegram Accounts to Deliver

  • Earliest identified Mach-O dropper variant (unobfuscated ARM64, later dubbed ZoomSDK.bin) first seen on campaign infrastructure.
  • Campaign operator using the persona "John" (Telegram handle @alchemy_john_mac) queried MAIV cryptocurrency group administrators about token vesting contracts, indicating active mid-campaign reconnaissance and rapport-building.
  • The "Aurora" Telegram exfiltration channel (bot @olise1212_bot, chat -1003951972810) was observed actively receiving stolen victim data through 2026-06-03.
  • An unobfuscated Mach-O dropper/stealer variant was recovered, exposing the full macOS credential-theft logic including the restrictiveMacOSDecoyAlternate() Chrome-keychain extraction routine.
  • Attacker fake-meeting HTML/JS kit build and versioning activity begins, running through 2026-07-14 across five recovered code revisions.
  • A new Mach-O dropper variant introduced LLVM control-flow-flattening obfuscation, indicating active tooling maturation.
  • zoom.05ukweb.uk confirmed as a live, active ClickFix execute-link lure domain via urlscan.io submission.
  • A "completion note" was added to the ClickFix clipboard-paste instructions shown to victims, indicating iterative social-engineering script tuning.
  • ClickFix lure wording revised to "If you allow the fix at the end, you'll see the success pop-up," the final observed iteration before public disclosure.
  • Newest Mach-O dropper variant introduced a new Telegram exfiltration bot ("Login PWD" / @pwin_first_bot, chat -1003876620740), replacing the earlier Aurora channel.
  • JUMPSEC publishes "Inside a DPRK BlueNoroff ClickFix Kit," disclosing the campaign after discovering exposed JavaScript source maps on live attacker infrastructure.
  • Cyber Security News publishes coverage of the JUMPSEC findings; threat ingested and tracked by Threadlinqs Intelligence as TL-2026-1720, cross-referenced against the related same-day skeleton TL-2026-1719.

Sources cited for BlueNoroff Hijacks Trusted Telegram Accounts to Deliver

Detection coverage for TL-2026-1720

As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1720 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
39 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1720

7 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats