logo

BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls

ID: bb26a05b-e3d2-5474-8df3-fe35ca4cd758

STIX ID: report--bb26a05b-e3d2-5474-8df3-fe35ca4cd758

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: Tushar Subhra Dutta

...
...

BlueNoroff (linked to the Lazarus ecosystem) is conducting a sophisticated campaign that commandeers real Telegram accounts to send fake Zoom/Teams meeting links to cryptocurrency and Web3 professionals; the lures profile browsers for crypto wallets and then deliver cross-platform malware—including PowerShell loaders, VBScript implants (Trojan.NukeSped / SLoad), macOS stealers and Mach-O droppers—to exfiltrate credentials and funds. The report details the attack chain, social-engineering techniques (deepfake video, clipboard-based ClickFix lure), extensive IoCs (SHA256 hashes, domains, IPs, filenames), and advises verifying invites on a second channel and inspecting true domains before executing commands or installers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.