Full Report
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. "BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet
Analysis Summary
# Threat Actor: BlueNoroff
## Attribution & Identity
- **Name:** BlueNoroff
- **Identity:** A North Korean (DPRK) state-sponsored threat group.
- **Aliases/Associated Groups:**
- A subgroup of the **Lazarus Group** (APT38).
- Associated with **UNC1069**.
- Operationally linked to a cluster tracked as **ClickFake Interview**.
- **Known Associations:** Often linked to the RGB (Reconnaissance General Bureau).
## Activity Summary
BlueNoroff is currently operating a sophisticated "ClickFix-style" victim acquisition platform. The campaign utilizes compromised legitimate contacts to distribute phishing links via Telegram. Targets are lured into fake Zoom or Microsoft Teams meetings where they encounter AI-generated deepfakes and social engineering prompts. The primary goal is to profile cryptocurrency wallets and deliver malware to high-value targets.
## Tactics, Techniques & Procedures
- **Social Engineering:** Leveraging compromised trusted contacts and hijacking Telegram accounts to send Calendly meeting invites.
- **Deepfake Technology:** Utilizing OpenAI ChatGPT and AI-generated headshots superimposed over authorized body movements to provide "plausible" video presence in fake meetings.
- **Webroot/Fingerprinting:** Execution of browser fingerprinting to inventory installed cryptocurrency wallets (e.g., MetaMask, Phantom) prior to malware delivery.
- **ClickFix Lure:** Tricking victims into running malicious commands/scripts (PowerShell/VBScript) under the guise of fixing audio/video "Zoom SDK" issues.
- **Session Hijacking:** Stealing Telegram sessions to self-propagate the attack through the victim’s contact list.
- **WebRTC Abuse:** Stealthily streaming the victim’s webcam to an operator’s panel using `mediasoup`.
- **MITRE ATT&CK IDs:**
- **T1566.002:** Phishing: Spearphishing Link
- **T1586.002:** Compromise Accounts: Email Accounts (Telegram/Social used here)
- **T1059.001:** Command and Scripting Interpreter: PowerShell
- **T1059.005:** Command and Scripting Interpreter: Visual Basic
- **T1204.002:** User Execution: Malicious File
## Targeting
- **Sectors:** Cryptocurrency, decentralized finance (DeFi), and major corporate entities.
- **Geography:** Global, with a focus on entities interacting with cryptocurrency markets.
- **Victims:** High-ranking employees of major companies and individuals within the cryptocurrency space.
## Tools & Infrastructure
- **Malware:**
- PowerShell loaders and VBScripts.
- ClickFix payloads.
- Cryptocurrency wallet reconnaissance modules.
- **Infrastructure:**
- Typosquatted/Fake domains impersonating `zoom[.]us` and `teams[.]microsoft[.]com`.
- **Calendly** for initial scheduling lures.
- **Telegram** for communication and propagation.
- **mediasoup WebRTC** for unauthorized webcam streaming.
- **Defanged Domains/IPs:** `zoom-us[.]limited`, `teams-microsoft[.]us` (exemplary types).
## Implications
BlueNoroff has successfully "operationalized trust." By combining AI-generated deepfakes with compromised legitimate social identities, they have significantly lowered the "uncanny valley" effect that typically alerts victims to phishing. Their selective targeting of high-value cryptocurrency wallets suggests a highly efficient and financially motivated operation designed to bypass traditional perimeter defenses through trust abuse.
## Mitigations
- **Verify Out-of-Band:** Confirm any unexpected meeting invites or requests to run software updates with contacts via a second communication channel (e.g., a phone call).
- **Control script execution:** Use AppLocker or Windows Defender Application Control (WDAC) to block unauthorized PowerShell and VBScript execution.
- **Browser Protection:** Use hardware security keys (FIDO2) for crypto-wallets to prevent simple credential/session theft.
- **Employee Training:** Educate staff on "ClickFix" tactics—specifically that legitimate services like Zoom or Teams will never ask users to run a PowerShell command to fix a camera issue.
- **Telegram Security:** Enable Two-Step Verification (2FA) on Telegram and regularly review "Active Sessions" in settings.