BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls
A North Korean hacking unit has refined a scheme that turns everyday chats into malware traps. The BlueNoroff group, linked to the wider Lazarus ecosystem, is taking over real Telegram accounts that belong to trusted industry contacts.
Those stolen identities then send fake Zoom and Microsoft Teams meeting links to senior staff at cryptocurrency and Web3 firms.
The motive is financial. Operators scan browsers for crypto wallets before they deliver malware, then aim to steal credentials and funds that can support state-backed goals.
The effort works less like a simple fake page and more like a repeatable pipeline that grows each time a new contact is compromised.
Analysts from Jumpsec identified the operation after operators left JavaScript source maps exposed on live servers.
Jumpsec said in a report shared with Cyber Security News (CSN) that the kit impersonates Zoom and Teams meetings while quietly profiling wallets and guiding victims into a ClickFix paste step.
The team rebuilt both Windows and macOS paths from the first lure through later theft stages. Trust is the real weapon. Victims hear from people they already know and may have met in person.
Advice to check the sender falls short because the account is genuine; only the person controlling it has changed. Patterns like this also appeared in a related new BlueNoroff campaign that used fake meeting pages against crypto professionals.
The harm spreads outward. Any infected machine with Telegram open can lose its session, feeding a loop that keeps bringing in fresh targets.
Firms that hold large digital assets remain prime prey because one successful breach can unlock serious value.
BlueNoroff Hijacks Trusted Telegram Accounts
In cases Jumpsec reviewed, hijacked Telegram accounts of real contacts messaged high-ranking employees at major companies.

A founder warning that their Telegram account was compromised. This capture victims chatting with those accounts without sensing the switch.

The invite looks ordinary at first glance. Links place familiar labels such as us.zoom on attacker-owned domains so the address feels safe.

After the user types a name and allows the camera, the page silently sends the webcam feed to an operator panel.
The victim then sits in a fake waiting room while the operator joins with a staged video built from AI headshots and real body motion.

Timed chat lines claim the microphone is failing and push a fake Zoom SDK update. That prompt opens the ClickFix box.
When the victim copies what seems like a simple fix, the clipboard is replaced with a harmful command, shown in Figure 12. The same social trick builds on the wider ClickFix lure technique seen in other malware drives.
Before any payload lands, the kit checks the browser for wallet tools such as MetaMask and related objects. Results flow to the operator panel so only high-value targets receive the full chain.
Zoom and Teams builds share the same core module, and a Google Meet string in the code hints that a third lure may exist. Readers who follow Lazarus Group crypto campaigns will recognize the long focus on DeFi trust and chat-based delivery.
Attack Chains and How to Stay Safe
On Windows, the pasted command runs a small PowerShell loader that fetches a VBScript implant classed as Trojan.NukeSped, a family tied to Lazarus tooling.
The script collects system data, browser extensions, and signs of Telegram use, then calls home for more payloads while trying to weaken local defenses.
On macOS, shell scripts pull fake Zoom or Teams installer apps that keep the user busy while a stealer reads Chrome keychain secrets and ships them out through Telegram bots.
Researchers found several Mach-O binaries and noted that some stealer builds had little obfuscation, which helped analysis. Supporting hosts clustered on one provider with many Zoom and Teams lookalike domains still live during the review.
For teams that already faced a fake Zoom meeting style trap, the warning is familiar: a brand name inside a link is not proof the site is real.
If you work in Web3 and receive a Zoom, Teams, or Meet invite over Telegram, even from someone you have known for months, confirm the plan on a second channel before you click.
Study the true domain, not only the subdomain labels. Real meeting tools never ask you to paste terminal commands to repair audio or camera problems. Treat trusted chat channels as part of your security edge, because BlueNoroff is counting on that trust to open the door.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA256 | 7a0b96f1063593a2e76f2f92ddfe091776a2ba63bc4f87f83dc5ebb675309d8d | PowerShell loader (Variant A) |
| SHA256 | 180f797723bd65e82189eb1f737d39ce522614a182e2b46b51faeb49953a412f | PowerShell loader (Variant B) |
| SHA256 | 8889f1b67aea6896945506dae192326149f6c5db87e9b04fa08ac9a142a87775 | VBScript implant (Trojan.NukeSped) |
| SHA256 | a86659dff126be72aff1d5e546baff735dcb7ed6ddd521737e7e3be8910c05f2 | VBScript implant (Trojan.SLoad) |
| SHA256 | 26bdad9189f6b28a90165c09ceed4386eff2fb352bea7fb78ebb164f28ebed28 | macOS shell script (template) |
| SHA256 | 163e4a72cbe392c073eddc60aee69dc1cf87ce492c375af74e923d75d8084683 | macOS shell script (deployed) |
| SHA256 | b149e207a3aad68605785710c58e8439aef61f48776c136d5a0ec6682d7dd2c0 | Mach-O dropper (ZoomSDK.bin) |
| SHA256 | 0517ca4649e33faefa3a6bfcd2707a8376a981be4b42b9d19146ebb93e7f8a35 | Mach-O dropper and stealer |
| SHA256 | 203bd56fbb75c9176fcbc77be6ff0792c9f55cb0ea3a255766130fadaa0c05de | Mach-O merged obfuscated build |
| SHA256 | eb78f46fd7cf28aacfbb4db1fdbaee8022e7874db6af588fe1c56b964c7c6833 | Mach-O merged build with new bot |
| Domain | callsdk.online | VBScript dropper C2 |
| Domain | weekly-up.online | Payload server (PS, VBS, macOS) |
| Domain | us.zoom.06webin.us | Zoom lure host |
| Domain | zoom.05ukweb.uk | Active execute-link host |
| Domain | microsoft-workspace.live | Zoom and Teams SPA host |
| Domain | webcamsdk-update.online | SDK-update themed C2 |
| Domain | meetsdk.online | Meeting SDK themed C2 |
| Domain | microteam.live | Fake Teams lure |
| Domain | cloud.inteam.live | Fake Teams lure |
| Domain | webapp.zoom.05live.co | Fake Zoom lure |
| Domain | edensun.xyz | XMPP and TURN relay host |
| IP | 144.172.110.53 | Kit domains and XMPP cluster |
| IP | 172.86.89.213 | Payload and macOS delivery server |
| IP | 172.86.91.195 | Domain rotation server |
| IP | 45.61.163.100 | Zoom lure infrastructure |
| IP | 45.61.163.113 | Teams and workspace lure host |
| IP | 45.61.163.43 | Zoom and Teams lure host |
| IP | 45.61.129.29 | zoom.05ukweb.uk host |
| Filename | oklnkae.vbs | Windows dropper in %TEMP% |
| Filename | NltOci4.vbs | Windows dropper in %TEMP% |
| Filename | ZoomApp.zip / TeamsApp.zip | macOS decoy installer apps |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.
The post BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls appeared first on Cyber Security News.
Tushar Subhra Dutta
Go to cyber-security-news