Threat reportMalwareTL-2026-1720
BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls
BlueNoroff Hijacks Trusted Telegram Accounts to Deliver (TL-2026-1720), also tracked as DPRK BlueNoroff ClickFix Kit, is a high-severity malware campaign, first published 2026-07-27. It is attributed to APT38 (North Korea) with high confidence, affects Zoom Video Communications Zoom (brand impersonated via typosquat lure, maps to 29 MITRE ATT&CK techniques (T1016, T1027, T1041), and is covered by 9 detection rules and 39 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 29MITRE ATT&CK
- Actors
- 1APT38
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 39Indicators of compromise
Key facts for TL-2026-1720
- Threat ID
- TL-2026-1720
- Also known as
- DPRK BlueNoroff ClickFix Kit, GhostCall-adjacent Telegram-hijack campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- APT38
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, web3, blockchain, financial services, venture capital
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 39
Malware and tooling in BlueNoroff Hijacks Trusted Telegram Accounts to Deliver
Malware and tooling: Trojan.NukeSped, Trojan.SLoad, ClickFix
How BlueNoroff Hijacks Trusted Telegram Accounts to Deliver works
BlueNoroff (DPRK, Lazarus-linked) hijacks compromised Telegram accounts of trusted industry contacts to lure Web3/crypto executives into fake Zoom/Teams meetings, sustains the deception with a pre-produced AI-generated deepfake operator video, then deploys a ClickFix clipboard-hijack chain delivering Trojan.NukeSped/Trojan.SLoad (Windows) and Mach-O droppers (macOS) to steal cryptocurrency wallet and Chrome-keychain credentials.
Between at least 2026-04-22 and 2026-07-15, BlueNoroff (a financially-motivated Lazarus Group sub-cluster also tracked as APT38/TA444/Sapphire Sleet/Stardust Chollima) ran a self-propagating social-engineering pipeline against cryptocurrency and Web3 executives. Compromised Telegram accounts belonging to real, trusted industry contacts are used to send fake Zoom or Microsoft Teams meeting invitations. Victims are redirected to attacker-owned typosquat domains (e.g. us.zoom.06webin.us, zoom.05ukweb.uk, microsoft-workspace.live) hosting a fake meeting client that silently captures webcam feed via WebRTC/mediasoup and fingerprints the browser for cryptocurrency wallets (EIP-6963 and legacy window.ethereum probing for MetaMask, plus Solana wallet detection) before the operator ever appears. Once a high-value wallet profile is confirmed, an operator joins the call and plays a pre-produced deepfake video composited from AI-generated headshots and real body motion harvested from prior victims' captured footage, sustaining the impression of a live human presence. A scripted social-engineering sequence (an on-time "can you hear me" opener, a false claim the meeting SDK is out of date, and an auto-advancing fake update progress bar) culminates in a ClickFix clipboard-hijack box: when the victim copies the displayed "fix" command, the clipboard contents are silently substituted with a malicious command. On Windows this launches a self-deleting PowerShell loader that downloads and double-executes a VBScript C2 implant (classified by VirusTotal as Trojan.NukeSped and Trojan.SLoad, both associated with the Lazarus Group), which disables Windows Defender via an Add-MpPreference exclusion, profiles the host (WMI domain/username, OS/CPU/timezone/network adapters, running processes, installed browser extensions, and Telegram IndexedDB usage across ten browser variants), and beacons recon data and execution status to attacker C2 before staging further PE payloads. On macOS the ClickFix command instead drops a shell script that self-deletes, displays a decoy ZoomApp.app/TeamsApp.app/SystemApp.app installer via osascript to keep the victim occupied, bypasses Gatekeeper (xattr -rc plus ad-hoc codesign), and executes a Mach-O ARM64 dropper (four observed builds, April-July 2026, progressively obfuscated with LLVM control-flow flattening) that version-gates on macOS >= 26.4 before running a Chrome-keychain stealer (`security find-generic-password -wa "Chrome"`) and exfiltrating the base64-encoded master key via a hardcoded Telegram bot (observed rotating from an "Aurora" channel in May-June to a "Login PWD" bot in July). Infected machines with an active Telegram session feed a self-propagation loop: the malware harvests the session, and the compromised account is used to approach the original victim's own trusted contacts, sustaining a continuous acquisition pipeline. All identified infrastructure (21 high-confidence domains, 9 IPs) sits behind Cloudzy/RouterHosting LLC (AS14956), a hosting provider previously documented supporting DPRK and Iranian APT infrastructure, and shares an identical XAMPP/Apache/PHP server fingerprint and AES-GCM-256 execute-link encryption scheme across all deployments. JUMPSEC discovered the campaign via exposed JavaScript source maps left on live attacker infrastructure and published findings on 2026-07-24; the technique, infrastructure pattern, and deepfake-meeting tradecraft closely mirror BlueNoroff's Arctic Wolf-documented April 2026 Web3 intrusion and Kaspersky's October 2025 GhostCall/GhostHire reporting, corroborating high-confidence attribution to the same actor and its ongoing SnatchCrypto operation.
MITRE ATT&CK techniques used in TL-2026-1720
Discovery
T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1518 Software Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1480 Execution Guardrails
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Collection
T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data; T1125 Video Capture
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1573 Encrypted Channel
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing
Credential Access
T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts
Affected products and versions in BlueNoroff Hijacks Trusted Telegram Accounts to Deliver
- Zoom Video Communications — Zoom (brand impersonated via typosquat lure domains)
Vulnerable versions: N/A - social engineering / brand impersonation, no product vulnerability - Microsoft — Microsoft Teams (brand impersonated via typosquat lure domains)
Vulnerable versions: N/A - social engineering / brand impersonation, no product vulnerability - Microsoft — Windows (PowerShell + Windows Script Host execution environment abused for loader and implant stages)
Vulnerable versions: All supported Windows versions with PowerShell and WSH (.vbs) enabled - Apple — macOS (Mach-O dropper and Chrome-keychain stealer, version-gated to execute only on newer releases)
Vulnerable versions: macOS 26.4 and later (stealer execution gate `kern.osproductversion`) - Google — Chrome (credentials stored in the macOS Keychain targeted via the `security` CLI)
Vulnerable versions: All versions storing generic passwords in macOS Keychain
Remediation for BlueNoroff Hijacks Trusted Telegram Accounts to Deliver
Immediate actions
- Block all listed C2/lure domains and IPs (see IOCs) at DNS resolver, perimeter firewall, and web proxy layers
- Alert on and isolate any Windows/macOS host observed resolving edensun.xyz or any Cloudzy/RouterHosting LLC (AS14956) IP in this record
- Hunt for oklnkae.vbs / NltOci4.vbs in %TEMP%, ZoomApp.app/TeamsApp.app/SystemApp.app decoy installers, and Add-MpPreference Windows Defender exclusions targeting C:\Users
- Force-rotate credentials and Chrome-stored passwords for any employee who joined an unscheduled Zoom/Teams call originating from a Telegram contact in the campaign window
- Revoke and re-issue active Telegram sessions org-wide for crypto/Web3 staff; enforce Telegram two-step verification
Workarounds
- Where feasible, restrict browser clipboard-paste execution/auto-run behavior for unmanaged or unrecognized meeting-platform sessions
- Permit Zoom/Teams client and SDK installation only via managed software deployment; block ad-hoc third-party SDK installers
Longer-term hardening
- Deploy EDR behavioral detection for clipboard-write hijacking (ClickFix) and for wscript.exe/osascript spawning outbound network connections
- Require out-of-band (phone/in-person) verification for meeting invites from previously-trusted contacts whose behavior or wording suddenly changes
- Restrict or closely monitor PowerShell, VBScript (WSH), and AppleScript execution on endpoints used by staff with cryptocurrency wallet access
- Monitor for ad-hoc codesign + xattr -rc invocations against newly downloaded macOS binaries as a Gatekeeper-bypass indicator
- Run recurring ClickFix/deepfake-meeting social-engineering awareness training for finance, executive, and Web3-facing staff
Timeline of BlueNoroff Hijacks Trusted Telegram Accounts to Deliver
- Earliest identified Mach-O dropper variant (unobfuscated ARM64, later dubbed ZoomSDK.bin) first seen on campaign infrastructure.
- Campaign operator using the persona "John" (Telegram handle @alchemy_john_mac) queried MAIV cryptocurrency group administrators about token vesting contracts, indicating active mid-campaign reconnaissance and rapport-building.
- The "Aurora" Telegram exfiltration channel (bot @olise1212_bot, chat -1003951972810) was observed actively receiving stolen victim data through 2026-06-03.
- An unobfuscated Mach-O dropper/stealer variant was recovered, exposing the full macOS credential-theft logic including the restrictiveMacOSDecoyAlternate() Chrome-keychain extraction routine.
- Attacker fake-meeting HTML/JS kit build and versioning activity begins, running through 2026-07-14 across five recovered code revisions.
- A new Mach-O dropper variant introduced LLVM control-flow-flattening obfuscation, indicating active tooling maturation.
- zoom.05ukweb.uk confirmed as a live, active ClickFix execute-link lure domain via urlscan.io submission.
- A "completion note" was added to the ClickFix clipboard-paste instructions shown to victims, indicating iterative social-engineering script tuning.
- ClickFix lure wording revised to "If you allow the fix at the end, you'll see the success pop-up," the final observed iteration before public disclosure.
- Newest Mach-O dropper variant introduced a new Telegram exfiltration bot ("Login PWD" / @pwin_first_bot, chat -1003876620740), replacing the earlier Aurora channel.
- JUMPSEC publishes "Inside a DPRK BlueNoroff ClickFix Kit," disclosing the campaign after discovering exposed JavaScript source maps on live attacker infrastructure.
- Cyber Security News publishes coverage of the JUMPSEC findings; threat ingested and tracked by Threadlinqs Intelligence as TL-2026-1720, cross-referenced against the related same-day skeleton TL-2026-1719.
Sources cited for BlueNoroff Hijacks Trusted Telegram Accounts to Deliver
- BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls
- Inside a DPRK BlueNoroff ClickFix Kit
- BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector
- BlueNoroff's latest campaigns: GhostCall and GhostHire
- Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains
- North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures
- BlueNoroff reemerges with new campaigns for crypto theft and espionage
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
Detection coverage for TL-2026-1720
As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1720 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1720
7 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.