BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector
ID: 9f20847e-870d-5c8a-ad7a-f14f21ce0556
STIX ID: report--9f20847e-870d-5c8a-ad7a-f14f21ce0556
Feed Name: Arctic Wolf Blog
**Executive Summary:** Arctic Wolf documents a targeted, high-confidence BlueNoroff (Lazarus subgroup) campaign that used Calendly-based social engineering and typo-squatted Zoom/Teams pages to render fake meetings, exfiltrate live webcam feeds, and deliver a ClickFix clipboard attack that led to a PowerShell in-memory C2 implant, browser-process injection delivering a Chromium credential stealer, Telegram session theft, UAC bypass, and persistent startup mechanisms; the investigation found a media/deepfake production pipeline and at least 100 targeted individuals (mostly Web3/crypto executives) with extensive attacker infrastructure and actionable IOCs and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
