BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls

BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls










A North Korean hacking unit has refined a scheme that turns everyday chats into malware traps. The BlueNoroff group, linked to the wider Lazarus ecosystem, is taking over real Telegram accounts that belong to trusted industry contacts.

Those stolen identities then send fake Zoom and Microsoft Teams meeting links to senior staff at cryptocurrency and Web3 firms.

The motive is financial. Operators scan browsers for crypto wallets before they deliver malware, then aim to steal credentials and funds that can support state-backed goals.

The effort works less like a simple fake page and more like a repeatable pipeline that grows each time a new contact is compromised.

Analysts from Jumpsec identified the operation after operators left JavaScript source maps exposed on live servers. 

Jumpsec said in a report shared with Cyber Security News (CSN) that the kit impersonates Zoom and Teams meetings while quietly profiling wallets and guiding victims into a ClickFix paste step.

The team rebuilt both Windows and macOS paths from the first lure through later theft stages. Trust is the real weapon. Victims hear from people they already know and may have met in person.

Advice to check the sender falls short because the account is genuine; only the person controlling it has changed. Patterns like this also appeared in a related new BlueNoroff campaign that used fake meeting pages against crypto professionals.

The harm spreads outward. Any infected machine with Telegram open can lose its session, feeding a loop that keeps bringing in fresh targets.

Firms that hold large digital assets remain prime prey because one successful breach can unlock serious value.

BlueNoroff Hijacks Trusted Telegram Accounts

In cases Jumpsec reviewed, hijacked Telegram accounts of real contacts messaged high-ranking employees at major companies.

A founder announcing their Telegram account as compromised (Source - Jumpsec)
A founder announcing their Telegram account as compromised (Source – Jumpsec)

A founder warning that their Telegram account was compromised. This capture victims chatting with those accounts without sensing the switch.

A victim (right, purple messages) messaging a compromised Telegram account (left) (Source - Jumpsec)
A victim (right, purple messages) messaging a compromised Telegram account (left) (Source – Jumpsec)

The invite looks ordinary at first glance. Links place familiar labels such as us.zoom on attacker-owned domains so the address feels safe.

The self-propagating system that continues to bring fresh victims in (Source - Jumpsec)
The self-propagating system that continues to bring fresh victims in (Source – Jumpsec)

After the user types a name and allows the camera, the page silently sends the webcam feed to an operator panel.

The victim then sits in a fake waiting room while the operator joins with a staged video built from AI headshots and real body motion.

Operator joins the fake call, and the simulated deepfake video plays (Source - Jumpsec)
Operator joins the fake call, and the simulated deepfake video plays (Source – Jumpsec)

Timed chat lines claim the microphone is failing and push a fake Zoom SDK update. That prompt opens the ClickFix box.

When the victim copies what seems like a simple fix, the clipboard is replaced with a harmful command, shown in Figure 12. The same social trick builds on the wider ClickFix lure technique seen in other malware drives.

Before any payload lands, the kit checks the browser for wallet tools such as MetaMask and related objects. Results flow to the operator panel so only high-value targets receive the full chain.

Zoom and Teams builds share the same core module, and a Google Meet string in the code hints that a third lure may exist. Readers who follow Lazarus Group crypto campaigns will recognize the long focus on DeFi trust and chat-based delivery.

Attack Chains and How to Stay Safe

On Windows, the pasted command runs a small PowerShell loader that fetches a VBScript implant classed as Trojan.NukeSped, a family tied to Lazarus tooling.

The script collects system data, browser extensions, and signs of Telegram use, then calls home for more payloads while trying to weaken local defenses.

On macOS, shell scripts pull fake Zoom or Teams installer apps that keep the user busy while a stealer reads Chrome keychain secrets and ships them out through Telegram bots.

Researchers found several Mach-O binaries and noted that some stealer builds had little obfuscation, which helped analysis. Supporting hosts clustered on one provider with many Zoom and Teams lookalike domains still live during the review.

For teams that already faced a fake Zoom meeting style trap, the warning is familiar: a brand name inside a link is not proof the site is real.

If you work in Web3 and receive a Zoom, Teams, or Meet invite over Telegram, even from someone you have known for months, confirm the plan on a second channel before you click.

Study the true domain, not only the subdomain labels. Real meeting tools never ask you to paste terminal commands to repair audio or camera problems. Treat trusted chat channels as part of your security edge, because BlueNoroff is counting on that trust to open the door.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA256 7a0b96f1063593a2e76f2f92ddfe091776a2ba63bc4f87f83dc5ebb675309d8d PowerShell loader (Variant A)
SHA256 180f797723bd65e82189eb1f737d39ce522614a182e2b46b51faeb49953a412f PowerShell loader (Variant B)
SHA256 8889f1b67aea6896945506dae192326149f6c5db87e9b04fa08ac9a142a87775 VBScript implant (Trojan.NukeSped)
SHA256 a86659dff126be72aff1d5e546baff735dcb7ed6ddd521737e7e3be8910c05f2 VBScript implant (Trojan.SLoad)
SHA256 26bdad9189f6b28a90165c09ceed4386eff2fb352bea7fb78ebb164f28ebed28 macOS shell script (template)
SHA256 163e4a72cbe392c073eddc60aee69dc1cf87ce492c375af74e923d75d8084683 macOS shell script (deployed)
SHA256 b149e207a3aad68605785710c58e8439aef61f48776c136d5a0ec6682d7dd2c0 Mach-O dropper (ZoomSDK.bin)
SHA256 0517ca4649e33faefa3a6bfcd2707a8376a981be4b42b9d19146ebb93e7f8a35 Mach-O dropper and stealer
SHA256 203bd56fbb75c9176fcbc77be6ff0792c9f55cb0ea3a255766130fadaa0c05de Mach-O merged obfuscated build
SHA256 eb78f46fd7cf28aacfbb4db1fdbaee8022e7874db6af588fe1c56b964c7c6833 Mach-O merged build with new bot
Domain callsdk.online VBScript dropper C2
Domain weekly-up.online Payload server (PS, VBS, macOS)
Domain us.zoom.06webin.us Zoom lure host
Domain zoom.05ukweb.uk Active execute-link host
Domain microsoft-workspace.live Zoom and Teams SPA host
Domain webcamsdk-update.online SDK-update themed C2
Domain meetsdk.online Meeting SDK themed C2
Domain microteam.live Fake Teams lure
Domain cloud.inteam.live Fake Teams lure
Domain webapp.zoom.05live.co Fake Zoom lure
Domain edensun.xyz XMPP and TURN relay host
IP 144.172.110.53 Kit domains and XMPP cluster
IP 172.86.89.213 Payload and macOS delivery server
IP 172.86.91.195 Domain rotation server
IP 45.61.163.100 Zoom lure infrastructure
IP 45.61.163.113 Teams and workspace lure host
IP 45.61.163.43 Zoom and Teams lure host
IP 45.61.129.29 zoom.05ukweb.uk host
Filename oklnkae.vbs Windows dropper in %TEMP%
Filename NltOci4.vbs Windows dropper in %TEMP%
Filename ZoomApp.zip / TeamsApp.zip macOS decoy installer apps

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

The post BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls appeared first on Cyber Security News.






Tushar Subhra Dutta





Go to cyber-security-news





Posted

in

, ,

by