The Attack Chain
Published 7/26/2026, 8:14:59 AM
BLUENOROFF, a North Korean state-sponsored threat actor, is currently executing a sophisticated campaign that weaponizes fake Zoom and Telegram applications to steal cryptocurrency assets. The attack specifically targets Web3 executives, CEOs, and founders through a "self-reinforcing" social engineering pipeline that uses compromised accounts to lure new victims into fraudulent video meetings [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/].
The Attack Chain
The campaign follows a multi-stage process designed to bypass traditional security measures:
- Initial Contact: Attackers use compromised Telegram accounts of previous victims to reach out to their professional networks. They often schedule meetings weeks in advance via Calendly to build legitimacy [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/].
- The "Meeting" Bait: Shortly before the scheduled call, the attacker replaces a legitimate meeting link with a typo-squatted Zoom or Teams URL (e.g.,
uu03webzoom[.]us) [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/]. - Deepfake Meeting Lobby: Victims land on a fake lobby featuring AI-generated avatars (created via GPT-4o) and deepfake composite videos of previous victims to simulate a real meeting environment [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/].
- ClickFix Infection: The fake app displays a "broken" audio/video state and prompts the victim to run a "fix" command. This is a ClickFix-style prompt that tricks the victim into running an obfuscated PowerShell script [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/].
- Malware Execution: The script executes fileless malware in-memory to evade antivirus. It establishes a C2 connection to steal browser credentials, hijack Telegram sessions (
tdata), and fingerprint MetaMask or other crypto wallet extensions [Source: https://jumpsec.com/bluenoroff-phishing-kit-evolution-july-2026/].
Key Campaign Metrics & Indicators
| Metric | Detail |
|---|---|
| Target Demographics | 80% Finance/Web3; 50% CEOs/Founders; 41% US-based [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/] |
| Peak Activity | 121 events/month (March 2026) [Note: not independently confirmed] |
| Malware Persistence | Observed up to 66 days [Note: not independently confirmed] |
| Typo-squat Pattern | [2 chars][2 digits]web[brand].[us/com/org] [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/] |
| Exfiltration Method | Uses Telegram Bot API to send screenshots and stolen data to attackers [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/] |
Malware Capabilities
The malware deployed through these fake applications is highly specialized for crypto theft:
- Wallet Fingerprinting: The kit scans for specific extension IDs (MetaMask, etc.) across Chrome, Edge, Brave, and other browsers to prioritize high-value targets [Source: https://jumpsec.com/bluenoroff-phishing-kit-evolution-july-2026/].
- Credential Theft: It extracts saved passwords and session cookies to gain access to exchange accounts and private keys [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/].
- Stealthy Exfiltration: It uses
System.Windows.Formsto capture in-memory screenshots, which are then sent via the Telegram Bot API to avoid detection by network monitoring tools [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/].
While the general mechanics of the campaign are well-documented, specific metrics regarding the total number of events and exact persistence durations lack broad independent verification beyond initial research reports. Users are advised to never run "fix" commands or scripts provided during video meeting lobbies.