# BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls

> BlueNoroff (DPRK, Lazarus-linked) hijacks compromised Telegram accounts of trusted industry contacts to lure Web3/crypto executives into fake Zoom/Teams meetings, sustains the deception with a pre-produced AI-generated deepfake operator video, then deploys a ClickFix clipboard-hijack chain delivering Trojan.NukeSped/Trojan.SLoad (Windows) and Mach-O droppers (macOS) to steal cryptocurrency wallet and Chrome-keychain credentials.

- **Published:** 2026-07-27T00:00:00Z
- **Last reviewed:** 2026-07-27T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1720
- **ID:** TL-2026-1720
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** APT38 (North Korea)
- **Detections:** 9 · **IOCs:** 39 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Between at least 2026-04-22 and 2026-07-15, BlueNoroff (a financially-motivated Lazarus Group sub-cluster also tracked as APT38/TA444/Sapphire Sleet/Stardust Chollima) ran a self-propagating social-engineering pipeline against cryptocurrency and Web3 executives. Compromised Telegram accounts belonging to real, trusted industry contacts are used to send fake Zoom or Microsoft Teams meeting invitations. Victims are redirected to attacker-owned typosquat domains (e.g. us.zoom.06webin.us, zoom.05ukweb.uk, microsoft-workspace.live) hosting a fake meeting client that silently captures webcam feed via WebRTC/mediasoup and fingerprints the browser for cryptocurrency wallets (EIP-6963 and legacy window.ethereum probing for MetaMask, plus Solana wallet detection) before the operator ever appears. Once a high-value wallet profile is confirmed, an operator joins the call and plays a pre-produced deepfake video composited from AI-generated headshots and real body motion harvested from prior victims' captured footage, sustaining the impression of a live human presence. A scripted social-engineering sequence (an on-time "can you hear me" opener, a false claim the meeting SDK is out of date, and an auto-advancing fake update progress bar) culminates in a ClickFix clipboard-hijack box: when the victim copies the displayed "fix" command, the clipboard contents are silently substituted with a malicious command. On Windows this launches a self-deleting PowerShell loader that downloads and double-executes a VBScript C2 implant (classified by VirusTotal as Trojan.NukeSped and Trojan.SLoad, both associated with the Lazarus Group), which disables Windows Defender via an Add-MpPreference exclusion, profiles the host (WMI domain/username, OS/CPU/timezone/network adapters, running processes, installed browser extensions, and Telegram IndexedDB usage across ten browser variants), and beacons recon data and execution status to attacker C2 before staging further PE payloads. On macOS the ClickFix command instead drops a shell script that self-deletes, displays a decoy ZoomApp.app/TeamsApp.app/SystemApp.app installer via osascript to keep the victim occupied, bypasses Gatekeeper (xattr -rc plus ad-hoc codesign), and executes a Mach-O ARM64 dropper (four observed builds, April-July 2026, progressively obfuscated with LLVM control-flow flattening) that version-gates on macOS >= 26.4 before running a Chrome-keychain stealer (`security find-generic-password -wa "Chrome"`) and exfiltrating the base64-encoded master key via a hardcoded Telegram bot (observed rotating from an "Aurora" channel in May-June to a "Login PWD" bot in July). Infected machines with an active Telegram session feed a self-propagation loop: the malware harvests the session, and the compromised account is used to approach the original victim's own trusted contacts, sustaining a continuous acquisition pipeline. All identified infrastructure (21 high-confidence domains, 9 IPs) sits behind Cloudzy/RouterHosting LLC (AS14956), a hosting provider previously documented supporting DPRK and Iranian APT infrastructure, and shares an identical XAMPP/Apache/PHP server fingerprint and AES-GCM-256 execute-link encryption scheme across all deployments. JUMPSEC discovered the campaign via exposed JavaScript source maps left on live attacker infrastructure and published findings on 2026-07-24; the technique, infrastructure pattern, and deepfake-meeting tradecraft closely mirror BlueNoroff's Arctic Wolf-documented April 2026 Web3 intrusion and Kaspersky's October 2025 GhostCall/GhostHire reporting, corroborating high-confidence attribution to the same actor and its ongoing SnatchCrypto operation.

## MITRE ATT&CK

- T1586 Compromise Accounts
- T1583 Acquire Infrastructure
- T1584 Compromise Infrastructure
- T1585 Establish Accounts
- T1199 Trusted Relationship
- T1078 Valid Accounts
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1685 Disable or Modify Tools
- T1553 Subvert Trust Controls
- T1070 Indicator Removal
- T1480 Execution Guardrails
- T1027 Obfuscated Files or Information
- T1555 Credentials from Password Stores
- T1539 Steal Web Session Cookie
- T1082 System Information Discovery
- T1057 Process Discovery
- T1518 Software Discovery
- T1087 Account Discovery
- T1016 System Network Configuration Discovery
- T1056 Input Capture
- T1115 Clipboard Data
- T1113 Screen Capture
- T1125 Video Capture
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1567 Exfiltration Over Web Service
- T1041 Exfiltration Over C2 Channel

## Sources

- [BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls](https://cybersecuritynews.com/bluenoroff-hijacks-trusted-telegram-accounts/)
- [Inside a DPRK BlueNoroff ClickFix Kit](https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/)
- [BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector](https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/)
- [BlueNoroff's latest campaigns: GhostCall and GhostHire](https://securelist.com/bluenoroff-apt-campaigns-ghostcall-and-ghosthire/117842/)
- [Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains](https://thehackernews.com/2025/10/researchers-expose-ghostcall-and.html)
- [North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures](https://www.infosecurity-magazine.com/news/bluenoroff-dprk-hackers-target/)
- [BlueNoroff reemerges with new campaigns for crypto theft and espionage](https://www.csoonline.com/article/4081001/bluenoroff-reemerges-with-new-campaigns-for-crypto-theft-and-espionage.html)
- [BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials](https://gbhackers.com/bluenoroff-fake-meeting-kit/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1720
