North Korean BlueNoroff Hackers Deploy Advanced ClickFix Phishing Kit Impersonating Zoom and Microsoft Teams to Target Cryptocurrency Assets

The North Korean state-sponsored threat actor known as BlueNoroff has significantly escalated its cyber-espionage and financial theft capabilities by operationalizing a sophisticated phishing kit designed to impersonate popular videoconferencing platforms like Zoom and Microsoft Teams. This latest campaign, characterized by its "ClickFix" methodology, represents a highly refined victim acquisition pipeline that integrates social engineering, deepfake technology, and automated wallet reconnaissance to drain cryptocurrency assets from high-value targets. According to a comprehensive technical analysis by cybersecurity firm JUMPSEC, the group has transitioned from isolated attacks to a repeatable, platform-driven model that exploits the inherent trust within professional and social networks.
The Architecture of the BlueNoroff Victim Acquisition Pipeline
The current campaign is built upon a foundation of compromised trust. Unlike traditional phishing efforts that rely on cold outreach via email, BlueNoroff operators leverage hijacked Telegram accounts belonging to legitimate industry contacts. These accounts, often belonging to individuals well-known within the cryptocurrency and venture capital sectors, are used to initiate contact with high-ranking employees at major firms. By masquerading as a trusted peer or a business associate the victim has met in person, the attackers bypass traditional skepticism and security filters.
The attack chain typically begins with a message suggesting a professional meeting, often accompanied by a Calendly link. When the victim clicks the link, they are redirected not to a legitimate scheduling service, but to a typosquatted domain that meticulously mimics the interface of Zoom or Microsoft Teams. These domains often utilize complex subdomains, such as "us.zoom.06webin.us," to create an air of authenticity that is difficult for the average user to distinguish from a genuine corporate URL.
Once the victim arrives at the phishing site, the platform initiates a multi-stage technical exploitation process. The site prompts the user to enter their name and grant permissions for webcam and microphone access. While the victim believes they are preparing for a standard video call, the kit utilizes mediasoup WebRTC technology to stealthily stream the victim’s webcam feed back to the attackers’ command-and-control (C2) panel. This allows the operators to monitor the victim in real-time, ensuring they are present and engaged before proceeding with the final stages of the attack.

The Role of AI and Deepfake Technology in Social Engineering
One of the most alarming aspects of the JUMPSEC report is the group’s use of artificial intelligence to enhance the credibility of the fake meetings. When a victim joins the "call," they are often presented with a video feed that appears to show a familiar face. This is not a live stream of the attacker, but a sophisticated composite video. BlueNoroff uses OpenAI’s ChatGPT and other generative tools to create high-quality headshots, which are then superimposed over authentic body movements recorded during previous legitimate meetings.
This "self-sustaining" cycle means that every successful compromise provides the attackers with new source material. By capturing the video and audio of one victim, the group can refine the deepfake assets used against that person’s own contacts. This creates a psychological trap: the victim sees a face they recognize, moving with natural body language, which reinforces the illusion of a legitimate business interaction. While the victim waits in a "holding room" or sees a message stating "waiting for other participants," the attackers are busy performing technical reconnaissance in the background.
Technical Reconnaissance and Malware Delivery
Simultaneous with the visual deception, the phishing kit executes a fingerprinting script within the victim’s web browser. This script is specifically designed to inventory installed cryptocurrency wallet extensions, such as MetaMask, Coinbase Wallet, or Phantom. By identifying the specific wallets in use, the attackers can tailor their subsequent malware delivery to maximize the chances of a successful "drainer" attack.
The final "ClickFix" hook is triggered when the operator sends a simulated system error message to the victim, claiming that their microphone or camera is not working due to an outdated software development kit (SDK). The victim is prompted to click a button to "Update Zoom SDK" or "Fix Audio." This action triggers the download and execution of a malicious payload. Because the request appears to come from within the "Zoom" application environment during a scheduled meeting, victims are significantly more likely to bypass their usual security protocols and run the executable.
JUMPSEC noted that the campaign is cross-platform, with distinct attack chains developed for both Windows and macOS. The malware delivery mechanism is highly targeted; if the browser fingerprinting indicates that the victim does not hold significant cryptocurrency assets, the attackers may choose not to deliver the final payload, thereby preserving the longevity of their infrastructure and avoiding unnecessary detection.

Chronology and Evolution of the Campaign
The evolution of this specific threat cluster has been tracked by various cybersecurity entities since early 2025.
- Early 2025: Initial reports emerge of North Korean actors using "ClickFix" lures—pretexts involving technical fixes for audio/video issues—to deliver malware.
- April 2025: Researchers identify the "ClickFake Interview" campaign, where threat actors posed as recruiters from major tech firms, using fake meeting links to target job seekers in the crypto space.
- May 2026: BlueNoroff operators are observed refining their infrastructure. A specific operator using the alias "John" (@alchemy_john_mac) is linked to Telegram bot tokens used for data exfiltration. This individual was seen interacting with cryptocurrency groups to discuss vesting contracts, likely as part of further reconnaissance.
- May 31 – July 14, 2026: JUMPSEC identifies five distinct versions of the phishing kit, indicating a rapid development cycle. Improvements include better mobile/tablet blocking, more polished Microsoft Teams clones, and advanced wallet probing capabilities.
- Current Status: The campaign remains active, with a primary focus on Zoom and Microsoft Teams due to their perceived requirement for desktop clients, which makes the "SDK update" pretext more believable than it would be for browser-native platforms like Google Meet.
Strategic Platform Selection: Why Zoom and Teams?
The JUMPSEC report provides a nuanced analysis of why BlueNoroff has prioritized Zoom and Microsoft Teams over other competitors. Sean Moran, head of threat research and enablement at JUMPSEC, highlights three primary factors:
- The "Heavyweight" Pretext: Both Zoom and Teams are associated with dedicated desktop applications. This makes the "SDK out of date" or "Driver fix" lure plausible to the user. In contrast, Google Meet is primarily browser-based, making a request to download a "fix" executable appear suspicious.
- Target Demographics: In the worlds of venture capital, institutional finance, and Web3 development, Zoom and Teams are the "standard" for high-stakes partnership and investor calls. Google Meet is often viewed as a more casual or customer-facing platform. By targeting the platforms used by executives, BlueNoroff ensures they are fishing in high-value waters.
- Typosquatting Surface: The complex subdomain structure of Zoom links (e.g., [company].zoom.us) provides an expansive surface for creating convincing fake URLs. It is significantly easier to trick a user with a variation of a Zoom subdomain than it is to spoof the more centralized "meet.google.com" structure.
Attribution and Global Implications
BlueNoroff is widely recognized by intelligence agencies and cybersecurity firms as a subgroup of the Lazarus Group, which operates under the direction of North Korea’s Reconnaissance General Bureau (RGB). While the broader Lazarus Group is known for destructive attacks and large-scale bank heists (such as the 2016 Bangladesh Bank robbery), BlueNoroff’s mandate is specifically focused on revenue generation through the theft of digital assets and cryptocurrency.
The financial motives behind these campaigns are clear. The North Korean state uses stolen cryptocurrency to fund its weapons programs and bypass international sanctions. By creating a repeatable "pipeline" for victim acquisition, BlueNoroff has moved beyond "hit-and-run" attacks toward a sustainable model of industrial-scale cybercrime.
The implications of this campaign extend far beyond the cryptocurrency sector. The integration of AI-generated deepfakes and the exploitation of trusted Telegram sessions represent a shift in the threat landscape where "identity" is the new perimeter. Organizations can no longer rely solely on technical controls like firewalls or antivirus software; they must account for the fact that a message from a known contact, appearing in a familiar app, and showing a familiar face, can still be a malicious fabrication.

Official Responses and Security Recommendations
While Zoom and Microsoft have not issued specific joint statements regarding this particular BlueNoroff kit, both companies have historically invested heavily in platform security and user education regarding phishing. Security researchers emphasize that the vulnerability being exploited is not a flaw in the videoconferencing software itself, but rather a sophisticated manipulation of human psychology and browser-level permissions.
To mitigate the risk of falling victim to such campaigns, JUMPSEC and other security experts recommend the following:
- Verify Out-of-Band: If a contact sends a meeting link via Telegram or another messaging app, verify the request through a different communication channel, such as an official corporate email or a phone call.
- Scrutinize URLs: Carefully examine meeting links for typosquatting. Be wary of complex subdomains or domains that do not end in the official "zoom.us" or "microsoft.com" suffixes.
- Treat "SDK Updates" with Suspicion: Legitimate videoconferencing platforms typically handle updates through their internal application settings or official app stores. Any prompt to download an executable "fix" from a browser window during a call should be treated as a major red flag.
- Implement Hardware Security Keys: For high-value employees, the use of physical security keys (like YubiKeys) can prevent the theft of sessions and provide a more robust defense against the malware delivered by these kits.
As BlueNoroff continues to refine its toolkit, the cybersecurity community warns that the line between reality and digital deception will only continue to blur. The "ClickFix" campaign serves as a stark reminder that in the modern era of cyber warfare, trust is the most dangerous vulnerability of all.







