Go to app

The Attack Chain

Published 7/26/2026, 8:14:59 AM

BLUENOROFF, a North Korean state-sponsored threat actor, is currently executing a sophisticated campaign that weaponizes fake Zoom and Telegram applications to steal cryptocurrency assets. The attack specifically targets Web3 executives, CEOs, and founders through a "self-reinforcing" social engineering pipeline that uses compromised accounts to lure new victims into fraudulent video meetings [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/].

The Attack Chain

The campaign follows a multi-stage process designed to bypass traditional security measures:

  1. Initial Contact: Attackers use compromised Telegram accounts of previous victims to reach out to their professional networks. They often schedule meetings weeks in advance via Calendly to build legitimacy [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/].
  2. The "Meeting" Bait: Shortly before the scheduled call, the attacker replaces a legitimate meeting link with a typo-squatted Zoom or Teams URL (e.g., uu03webzoom[.]us) [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/].
  3. Deepfake Meeting Lobby: Victims land on a fake lobby featuring AI-generated avatars (created via GPT-4o) and deepfake composite videos of previous victims to simulate a real meeting environment [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/].
  4. ClickFix Infection: The fake app displays a "broken" audio/video state and prompts the victim to run a "fix" command. This is a ClickFix-style prompt that tricks the victim into running an obfuscated PowerShell script [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/].
  5. Malware Execution: The script executes fileless malware in-memory to evade antivirus. It establishes a C2 connection to steal browser credentials, hijack Telegram sessions (tdata), and fingerprint MetaMask or other crypto wallet extensions [Source: https://jumpsec.com/bluenoroff-phishing-kit-evolution-july-2026/].

Key Campaign Metrics & Indicators

MetricDetail
Target Demographics80% Finance/Web3; 50% CEOs/Founders; 41% US-based [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/]
Peak Activity121 events/month (March 2026) [Note: not independently confirmed]
Malware PersistenceObserved up to 66 days [Note: not independently confirmed]
Typo-squat Pattern[2 chars][2 digits]web[brand].[us/com/org] [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/]
Exfiltration MethodUses Telegram Bot API to send screenshots and stolen data to attackers [Source: https://arcticwolf.com/resources/blog/bluenoroff-fake-zoom-telegram-attack-campaign/]

Malware Capabilities

The malware deployed through these fake applications is highly specialized for crypto theft:

While the general mechanics of the campaign are well-documented, specific metrics regarding the total number of events and exact persistence durations lack broad independent verification beyond initial research reports. Users are advised to never run "fix" commands or scripts provided during video meeting lobbies.