BlueNoroff's Evolving ClickFix Campaigns Target Crypto Pros with Sophisticated Zoom & Teams Phishing
North Korean threat actors, identified as **BlueNoroff**, are leveraging an advanced phishing kit in their **ClickFix-style campaigns**. These sophisticated attacks employ typosquatted **Zoom** and **Microsoft Teams** domains, combined with social engineering and AI-generated deepfakes, to deliver malware and compromise high-value targets in the cryptocurrency sector.
A detailed report by **JUMPSEC** reveals that North Korean threat actors, known as **BlueNoroff**, are actively deploying a sophisticated phishing kit. This kit is central to their **ClickFix-style campaigns**, which exploit typosquatted **Zoom** and **Microsoft Teams** domains to ensnare victims in social engineering schemes designed for malware delivery.
"**BlueNoroff** has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet reconnaissance and malware delivery into a repeatable victim acquisition pipeline," **JUMPSEC** states in their report. "The platform profiles victims' cryptocurrency wallets before malware delivery, enabling selective targeting of high-value victims."
Describing the operation as an operator-driven victim acquisition platform, **JUMPSEC** highlights that these attacks initiate by using compromised trusted contacts as the initial access vector. This strategy creates a self-propagating attack chain, primarily disseminated via **Telegram**.

Previous documentation of this activity dates back to early 2025, with **Sekoia** tracking a related North Korea-aligned threat cluster dubbed **ClickFake Interview**. This group utilizes similar **ClickFix**-like lures, often under the guise of addressing camera or audio issues, to trick unsuspecting targets into executing malicious commands.
### The Attack Chain: From Trust to Compromise
**BlueNoroff**'s tactics involve distributing lure links from accounts that targets already trust and may have even met in person. Attackers hijack legitimate **Telegram** accounts belonging to individuals in the cryptocurrency space to message high-ranking employees of major companies, sharing seemingly innocuous **Calendly** meeting links.
"Every victim who runs the payload with **Telegram Web** open or **Telegram Desktop** installed is a candidate for their **Telegram** session to be stolen and reused against their own contacts," **JUMPSEC** warns, emphasizing the self-sustaining nature of the campaign where one compromised account fuels the next.
The **Calendly** link directs victims to what appears to be a legitimate **Zoom** meeting URL. However, it's a meticulously crafted fake domain impersonating the videoconferencing service. Upon landing on this phishing page, users are prompted to enter their name and grant permissions to access their webcam. Once granted, the webcam stream is covertly transmitted to the operators' panel via **mediasoup WebRTC**.

In the final stage, after the victim seemingly joins the meeting, they are presented with a page indicating they are alone in the call, with a message like "waiting for other participants." This sets the stage for the next phase of the attack.
"Once the victim has joined, the operator can then continue to use their panel in order to control the meeting, send fake 'your mic isn't working' messages, and trigger the 'Zoom SDK Update,' ultimately resulting in the **ClickFix** payload," **JUMPSEC** explains.
Simultaneously, the kit performs a browser fingerprinting step to inventory installed cryptocurrency wallets. Following this, a fake "admin" joins the meeting. Crucially, the video the victim sees is not a live stream but a pre-edited deepfake, featuring **AI-generated headshots** created using **OpenAI ChatGPT** superimposed over authentic body movements captured from previous meetings.
"So, each successful attack feeds source material into the composites used against the next target," **JUMPSEC** elaborates. "This combined with the **Telegram** account takeover method means that the fake meeting shows a plausibly familiar-looking face, moving with the body language of someone who was actually captured on camera."
### Platform Variations and Kill Chains
**JUMPSEC** observed two distinct lure variants, one for **Zoom** and another for **Microsoft Teams**. The **Teams** variant is notably more refined, supporting emoji reactions, blocking mobile/tablet access, and advanced wallet probes before malware delivery.
Both **Windows** and **macOS** are targeted by the **ClickFix** attack chains:
* **Windows Kill Chain:**
* The **ClickFix** command executes a **PowerShell** loader that downloads and runs a **VBScript**.
* This **VBScript** disables **Microsoft Defender**, adds the "C:\Users" folder to the exclusion path, and force-restarts **Defender** to apply these exclusions.
* The implant checks for **Telegram Web**-related files within **Google Chrome**, **Microsoft Edge**, **Brave**, and **Mozilla Firefox** profile directories, likely to hijack **Telegram** session cookies.
* It enumerates installed extensions across various browsers (**Chrome**, **Chrome Beta**, **Chrome Dev**, **Chromium**, **Edge**, **Brave**, **Opera**, **Opera GX**, **Vivaldi**, and **Firefox**), reporting their extension IDs to identify known wallet extensions like **MetaMask** for high-value targeting.
* The implant can also deliver subsequent payloads, though their exact nature remains undisclosed.
* **macOS Kill Chain:**
* The **ClickFix** command runs a shell script, which then downloads a fake **Teams** (or **Zoom**) installer.
* The installer deploys the main stealer payload, designed to extract and exfiltrate sensitive data, including system metadata and **Google Chrome** master keys from the **iCloud Keychain**, to the attacker via a **Telegram** channel named "Aurora." This also enables the deployment of additional payloads.
### Operator Identification and Infrastructure Development
Further analysis revealed that the **Telegram** exfiltration function hard-codes the bot token and chat ID within the stealer binary. Querying the **Telegram API** with this bot token linked it to an operator identified as "John" (**@alchemy_john_mac**). This individual was observed as recently as May 2026, inquiring with administrators of the **MAIV** cryptocurrency group about vesting contracts and fund withdrawals.
Examination of the threat actor's infrastructure uncovered five distinct versions of the phishing kit between May 31 and July 14, 2026, indicating active development and continuous refinement.
### Why Zoom and Teams?
Sean Moran, Head of Threat Research and Enablement at **JUMPSEC**, highlighted three key reasons for the campaign's specific focus on **Zoom** and **Teams** over platforms like **Google Meet**:
1. **ClickFix Pretext:** The core lure, "Zoom/Teams SDK out of date," capitalizes on the perception of these platforms having heavyweight desktop clients. **Google Meet**, being primarily browser-based, doesn't fit this narrative as seamlessly.
2. **Target-Application Fit:** **Zoom** and **Teams** are prevalent in the finance world, particularly among cryptocurrency, venture capital, and founder communities, making them ideal for "investor/partnership calls." **Google Meet** is often perceived as more of a general customer calling platform.
3. **Typosquatting Surface:** Domain schemes like "us.zoom.06webin.us" are highly effective for spoofing legitimate **Zoom** links due to their similarity with real sub-domains. In contrast, "meet.google.com" is more challenging to typosquat effectively.
Moran also noted that while the phishing kit currently only features **Zoom** and **Teams** lure pages, a **Google Meet** equivalent exists as an unimplemented stub in the source code. This suggests a deliberate strategic choice based on the aforementioned factors and the current success of the existing setup.
"The implications extend beyond this specific campaign. As **Web3** and digital assets continue to mature, threat actors are increasingly recognising that compromising the individuals who control access can be as valuable as attacking the infrastructure itself," **JUMPSEC** concluded, underscoring the escalating importance of robust identity and relationship security in the digital asset space.