Skip to content
Data Breach

BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls

A North Korean hacking unit has refined a scheme that turns everyday chats into malware traps. The BlueNoroff group, linked to the wider Lazarus ecosystem, is taking over real Telegram accounts that belong to trusted industry contacts. Those stolen identities then send fake Zoom and Microsoft Teams...

· Jul 27, 2026 · 6 min read · 👁 0 views
BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls

A North Korean hacking unit has refined a scheme that turns everyday chats into malware traps. The BlueNoroff group, linked to the wider Lazarus ecosystem, is taking over real Telegram accounts that belong to trusted industry contacts.

Those stolen identities then send fake Zoom and Microsoft Teams meeting links to senior staff at cryptocurrency and Web3 firms.

The motive is financial. Operators scan browsers for crypto wallets before they deliver malware, then aim to steal credentials and funds that can support state-backed goals.

The effort works less like a simple fake page and more like a repeatable pipeline that grows each time a new contact is compromised.

Analysts from Jumpsec identified the operation after operators left JavaScript source maps exposed on live servers. 

Jumpsec said in a report shared with Cyber Security News (CSN) that the kit impersonates Zoom and Teams meetings while quietly profiling wallets and guiding victims into a ClickFix paste step.

The team rebuilt both Windows and macOS paths from the first lure through later theft stages. Trust is the real weapon. Victims hear from people they already know and may have met in person.

Advice to check the sender falls short because the account is genuine; only the person controlling it has changed. Patterns like this also appeared in a related new BlueNoroff campaign that used fake meeting pages against crypto professionals.

The harm spreads outward. Any infected machine with Telegram open can lose its session, feeding a loop that keeps bringing in fresh targets.

Firms that hold large digital assets remain prime prey because one successful breach can unlock serious value.

BlueNoroff Hijacks Trusted Telegram Accounts

In cases Jumpsec reviewed, hijacked Telegram accounts of real contacts messaged high-ranking employees at major companies.

A founder announcing their Telegram account as compromised (Source - Jumpsec)
A founder announcing their Telegram account as compromised (Source – Jumpsec)

A founder warning that their Telegram account was compromised. This capture victims chatting with those accounts without sensing the switch.

A victim (right, purple messages) messaging a compromised Telegram account (left) (Source - Jumpsec)
A victim (right, purple messages) messaging a compromised Telegram account (left) (Source – Jumpsec)

The invite looks ordinary at first glance. Links place familiar labels such as us.zoom on attacker-owned domains so the address feels safe.

The self-propagating system that continues to bring fresh victims in (Source - Jumpsec)
The self-propagating system that continues to bring fresh victims in (Source – Jumpsec)

After the user types a name and allows the camera, the page silently sends the webcam feed to an operator panel.

The victim then sits in a fake waiting room while the operator joins with a staged video built from AI headshots and real body motion.

Operator joins the fake call, and the simulated deepfake video plays (Source - Jumpsec)
Operator joins the fake call, and the simulated deepfake video plays (Source – Jumpsec)

Timed chat lines claim the microphone is failing and push a fake Zoom SDK update. That prompt opens the ClickFix box.

When the victim copies what seems like a simple fix, the clipboard is replaced with a harmful command, shown in Figure 12. The same social trick builds on the wider ClickFix lure technique seen in other malware drives.

Before any payload lands, the kit checks the browser for wallet tools such as MetaMask and related objects. Results flow to the operator panel so only high-value targets receive the full chain.

Zoom and Teams builds share the same core module, and a Google Meet string in the code hints that a third lure may exist. Readers who follow Lazarus Group crypto campaigns will recognize the long focus on DeFi trust and chat-based delivery.

Attack Chains and How to Stay Safe

On Windows, the pasted command runs a small PowerShell loader that fetches a VBScript implant classed as Trojan.NukeSped, a family tied to Lazarus tooling.

The script collects system data, browser extensions, and signs of Telegram use, then calls home for more payloads while trying to weaken local defenses.

On macOS, shell scripts pull fake Zoom or Teams installer apps that keep the user busy while a stealer reads Chrome keychain secrets and ships them out through Telegram bots.

Researchers found several Mach-O binaries and noted that some stealer builds had little obfuscation, which helped analysis. Supporting hosts clustered on one provider with many Zoom and Teams lookalike domains still live during the review.

For teams that already faced a fake Zoom meeting style trap, the warning is familiar: a brand name inside a link is not proof the site is real.

If you work in Web3 and receive a Zoom, Teams, or Meet invite over Telegram, even from someone you have known for months, confirm the plan on a second channel before you click.

Study the true domain, not only the subdomain labels. Real meeting tools never ask you to paste terminal commands to repair audio or camera problems. Treat trusted chat channels as part of your security edge, because BlueNoroff is counting on that trust to open the door.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
SHA2567a0b96f1063593a2e76f2f92ddfe091776a2ba63bc4f87f83dc5ebb675309d8dPowerShell loader (Variant A)
SHA256180f797723bd65e82189eb1f737d39ce522614a182e2b46b51faeb49953a412fPowerShell loader (Variant B)
SHA2568889f1b67aea6896945506dae192326149f6c5db87e9b04fa08ac9a142a87775VBScript implant (Trojan.NukeSped)
SHA256a86659dff126be72aff1d5e546baff735dcb7ed6ddd521737e7e3be8910c05f2VBScript implant (Trojan.SLoad)
SHA25626bdad9189f6b28a90165c09ceed4386eff2fb352bea7fb78ebb164f28ebed28macOS shell script (template)
SHA256163e4a72cbe392c073eddc60aee69dc1cf87ce492c375af74e923d75d8084683macOS shell script (deployed)
SHA256b149e207a3aad68605785710c58e8439aef61f48776c136d5a0ec6682d7dd2c0Mach-O dropper (ZoomSDK.bin)
SHA2560517ca4649e33faefa3a6bfcd2707a8376a981be4b42b9d19146ebb93e7f8a35Mach-O dropper and stealer
SHA256203bd56fbb75c9176fcbc77be6ff0792c9f55cb0ea3a255766130fadaa0c05deMach-O merged obfuscated build
SHA256eb78f46fd7cf28aacfbb4db1fdbaee8022e7874db6af588fe1c56b964c7c6833Mach-O merged build with new bot
Domaincallsdk.onlineVBScript dropper C2
Domainweekly-up.onlinePayload server (PS, VBS, macOS)
Domainus.zoom.06webin.usZoom lure host
Domainzoom.05ukweb.ukActive execute-link host
Domainmicrosoft-workspace.liveZoom and Teams SPA host
Domainwebcamsdk-update.onlineSDK-update themed C2
Domainmeetsdk.onlineMeeting SDK themed C2
Domainmicroteam.liveFake Teams lure
Domaincloud.inteam.liveFake Teams lure
Domainwebapp.zoom.05live.coFake Zoom lure
Domainedensun.xyzXMPP and TURN relay host
IP144.172.110.53Kit domains and XMPP cluster
IP172.86.89.213Payload and macOS delivery server
IP172.86.91.195Domain rotation server
IP45.61.163.100Zoom lure infrastructure
IP45.61.163.113Teams and workspace lure host
IP45.61.163.43Zoom and Teams lure host
IP45.61.129.29zoom.05ukweb.uk host
Filenameoklnkae.vbsWindows dropper in %TEMP%
FilenameNltOci4.vbsWindows dropper in %TEMP%
FilenameZoomApp.zip / TeamsApp.zipmacOS decoy installer apps

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you