North Korean Threat Actors Operate Sophisticated Phishing Kit Targeting Zoom and Microsoft Teams Users for Cryptocurrency Theft

North Korean threat actors, operating under the banner of the financially motivated group BlueNoroff, have been identified as the architects behind an advanced phishing campaign that leverages typosquatted domains for Zoom and Microsoft Teams. This sophisticated operation is not merely about tricking users into clicking malicious links; it’s a meticulously crafted victim acquisition pipeline designed to compromise cryptocurrency wallets and extract valuable digital assets. Security researchers at JUMPSEC have detailed how this campaign, dubbed "ClickFix-style campaigns," combines compromised industry contacts, social engineering, and real-time wallet reconnaissance to achieve its objectives.
The Mechanics of the ClickFix Campaign
The core of the ClickFix campaign revolves around a deceptive lure that preys on users’ reliance on popular communication platforms like Zoom and Microsoft Teams. Attackers craft messages, often appearing to originate from trusted contacts within the cryptocurrency sector, that prompt recipients to address an urgent issue related to their video conferencing software. These messages frequently suggest that the user’s Zoom or Teams application is outdated or malfunctioning, requiring an immediate "update" or "fix."
This pretext is crucial. By targeting applications like Zoom and Teams, which are widely adopted by businesses and individuals for professional and financial discussions, the attackers create a plausible scenario for a user to act without suspicion. The urgency of potential meeting disruptions or the need for uninterrupted communication in the fast-paced cryptocurrency world further motivates victims to comply with the malicious instructions.
Initial Access and Self-Propagation
A key innovation in this campaign is its reliance on compromised trusted contacts as the initial vector. Attackers gain access to legitimate Telegram accounts belonging to individuals within the cryptocurrency space. These compromised accounts are then used to send phishing messages to the contacts of the account owner, effectively creating a self-propagating attack chain. This tactic is highly effective because messages originating from a known and trusted source are far more likely to be opened and acted upon.
"BlueNoroff has operationalized trust abuse by combining compromised industry contacts, social engineering, wallet reconnaissance and malware delivery into a repeatable victim acquisition pipeline," JUMPSEC stated in a comprehensive report shared with The Hacker News. This "pipeline" is designed for efficiency and repeatability, allowing the threat actors to scale their operations.
The cybersecurity firm highlighted that the activity involves using these compromised contacts as the initial access vector, setting in motion a self-propagating attack chain that often utilizes Telegram for communication and distribution. This method of exploiting existing relationships and communication channels underscores the evolving sophistication of cyber threats.

A Chronology of Evolving Tactics
The observed activities of BlueNoroff and related North Korean threat clusters have been under scrutiny for some time. While the ClickFix-style campaigns are a recent focus, the underlying tactics and motivations are consistent with previous reports.
- Early 2025: Researchers began documenting activity that displayed similarities to the current ClickFix campaigns. This period likely saw the initial development and testing of some of the core components.
- Mid-2025: Sekoia, another cybersecurity research firm, identified a second related North Korea-aligned threat cluster, which they dubbed "ClickFake Interview." This cluster also employed ClickFix-like lures, specifically using the pretexts of addressing camera or audio issues to trick unsuspecting targets into executing malicious commands. This indicates a coordinated effort or at least parallel development by North Korean state-sponsored actors.
- Late 2025 – Early 2026: The ClickFix campaign, as detailed by JUMPSEC, began to mature, incorporating more advanced techniques such as wallet reconnaissance and the use of AI-generated deepfakes. The observed development and refinement of the phishing kit infrastructure, with five distinct versions appearing between May 31 and July 14, 2026, point to continuous adaptation and improvement by the threat actors.
The Deceptive Journey to Malware Delivery
The attack chain begins with a seemingly innocuous Calendly meeting link, sent via Telegram from a compromised account. This link is designed to direct the victim to a fake domain that expertly impersonates Zoom. Upon landing on this phishing page, users are prompted to enter their name and grant permissions for webcam access. This seemingly harmless request is the first critical step in the compromise.
"Every victim who runs the payload with Telegram Web open or Telegram Desktop installed is a candidate for their Telegram session to be stolen and reused against their own contacts," JUMPSEC explained, underscoring the self-sustaining nature of the campaign. Once a victim’s Telegram session is compromised, the attackers can leverage that account to further spread the phishing campaign within their own network of contacts.
Once webcam permissions are granted, the stream is covertly transmitted to the operators’ control panel using mediasoup WebRTC technology. This allows attackers to monitor potential victims in real-time, gathering intelligence or even preparing for the next stage of the attack.
The Phishing Kit: An Operator’s Control Panel
The operators’ panel is a sophisticated interface that provides attackers with a range of functionalities. It allows them to manage ongoing attacks, monitor victim activity, and orchestrate the final payload delivery. The ability to control the meeting, send fake messages, and trigger "Zoom SDK Updates" are all features designed to lull the victim into a false sense of security while simultaneously executing the malicious code.
One of the most chilling aspects of this campaign is the use of pre-edited videos featuring AI-generated headshots. These deepfakes are superimposed over authentic body movements captured during previous meetings. This creates a disturbingly plausible scenario where the victim believes they are in a real Zoom call, potentially with a familiar face.
"So, each successful attack feeds source material into the composites used against the next target," JUMPSEC explained. "This combined with the Telegram account takeover method means that the fake meeting shows a plausibly familiar-looking face, moving with the body language of someone who was actually captured on camera." This advanced use of AI in phishing attacks represents a significant escalation in the sophistication of social engineering tactics.

Targeting High-Value Victims: Cryptocurrency Wallet Reconnaissance
Before the malware is even delivered, the ClickFix kit executes a crucial reconnaissance step: fingerprinting the victim’s web browser to identify installed cryptocurrency wallets. This "wallet reconnaissance" allows BlueNoroff to selectively target individuals who are likely to possess high-value digital assets.
"The platform profiles victims’ cryptocurrency wallets before malware delivery, enabling selective targeting of high-value victims," JUMPSEC reported. This strategic approach ensures that the attackers’ efforts are focused on individuals who can provide the greatest financial return. By understanding the victim’s cryptocurrency holdings, the threat actors can tailor their subsequent actions for maximum impact.
Lure Variants: Zoom and Teams Under Scrutiny
JUMPSEC identified two distinct lure variants, one for Zoom and one for Microsoft Teams. The Teams variant is noted as being more polished, incorporating features such as emoji reactions, mobile/tablet blocking, and more advanced wallet probes prior to malware delivery. This suggests a continuous development cycle where successful features are incorporated into newer versions of the phishing kit.
The ClickFix attack chains have been engineered to be compatible with both Windows and macOS operating systems, broadening the potential victim pool.
Why Zoom and Teams? A Strategic Analysis
Sean Moran, head of threat research and enablement at JUMPSEC, offered a detailed analysis of why Zoom and Teams are the primary targets of this campaign. He outlined three key reasons:
- ClickFix Pretext: The "Zoom/Teams SDK out of date" lure is highly effective because it targets applications that users perceive as having substantial desktop clients. Google Meet, being primarily browser-based, doesn’t lend itself as well to this specific pretext.
- Target-Application Fit: Zoom and Teams are the default communication platforms for many in the cryptocurrency and venture capital sectors, as well as founders in the finance world. Google Meet, while widely used, is often perceived as more of a general customer-facing platform rather than a primary channel for investor or partnership calls.
- Typosquatting Surface: The domain naming schemes employed by the attackers, such as "us.zoom.06webin.us," are highly similar to legitimate Zoom links, making them easy to fall for. The structure of these domains, with numerous subdomains, provides a fertile ground for typosquatting and spoofing, whereas the simpler "meet.google.com" is more difficult to mimic effectively.
Moran also pointed out that while the current phishing kit primarily features Zoom and Teams lures, the source code for a Google Meet equivalent exists as an unimplemented stub. This suggests that the exclusion of Google Meet is a deliberate strategic choice based on the factors mentioned above and the current success of the existing lures.
The Human Element: The "John" Operator
Further analysis of the threat actor infrastructure has revealed a critical piece of information: the Telegram exfiltration function hard-codes the bot token and chat ID within the stealer binary. Querying the Telegram API for this bot token has linked it to an operator identified by the alias "John," with the Telegram handle "@alchemy_john_mac."

As recently as May 2026, this individual was observed interacting with administrators of the MAIV cryptocurrency group, inquiring about vesting contracts and the process for withdrawing funds. This provides a glimpse into the operational methods and financial interests of at least one individual involved in the campaign. The fact that a specific operator can be identified, even with an alias, highlights the operational security (OpSec) failures that can occur even within sophisticated threat actor groups.
Broader Implications for Cybersecurity and Web3
The BlueNoroff ClickFix campaign is a stark reminder of the evolving threat landscape, particularly in the realm of digital assets and decentralized finance (Web3). As these technologies mature, threat actors are increasingly recognizing that compromising the individuals who control access to valuable digital assets can be as lucrative, if not more so, than directly attacking the underlying infrastructure.
"The implications extend beyond this specific campaign," JUMPSEC concluded. "As Web3 and digital assets continue to mature, threat actors are increasingly recognising that compromising the individuals who control access can be as valuable as attacking the infrastructure itself."
The continuous refinement of BlueNoroff’s tactics demonstrates a clear and present danger to organizations and individuals operating in the cryptocurrency and blockchain space. The campaign’s success hinges on exploiting human trust and leveraging sophisticated technical means to bypass traditional security measures. This underscores the critical need for organizations to adopt a holistic security posture that extends beyond technical defenses to encompass the human element.
"BlueNoroff’s continued refinement demonstrates that organisations must consider identity, relationships and communication channels as critical parts of their security posture," the report emphasized. This means fostering strong security awareness among employees, implementing robust authentication mechanisms, and carefully vetting communication channels and contacts, especially when dealing with sensitive financial information. The sophistication of this campaign serves as a wake-up call for the industry to prioritize the security of individual access points and digital identities in an increasingly interconnected and asset-rich digital world.







