North Korean Cybercriminals Exploit Trust and Technology in Sophisticated Zoom and Teams Phishing Campaigns

North Korean threat actors, operating under the banner of the notorious BlueNoroff group, have been meticulously refining and deploying a sophisticated phishing kit, dubbed "ClickFix," to target users of popular communication platforms like Zoom and Microsoft Teams. This operation, characterized by its innovative use of typosquatted domains and social engineering tactics, aims to steal cryptocurrency by compromising trusted contacts and delivering carefully crafted malware. The latest findings, detailed in a comprehensive report by cybersecurity firm JUMPSEC, reveal a highly operationalized victim acquisition pipeline that leverages compromised industry connections, advanced social engineering, and even wallet reconnaissance before the final malware payload is deployed.
The ClickFix campaigns have been a growing concern since early 2025, with cybersecurity researchers consistently documenting the evolving tactics of North Korea-aligned threat clusters. Sekoia, another prominent security firm, has identified a related cluster known as "ClickFake Interview," which employs similar lures to trick victims into executing malicious commands, often under the guise of resolving camera or audio issues during simulated meetings. This particular focus on the functionality of communication tools highlights the attackers’ understanding of user vulnerabilities and their reliance on the perceived legitimacy of these platforms for business and professional interactions.
The Anatomy of a ClickFix Attack
At the core of the ClickFix operation is an operator-driven victim acquisition platform designed for repeatability and scalability. The initial access vector is particularly insidious: attackers compromise legitimate Telegram accounts belonging to trusted individuals within the cryptocurrency and finance sectors. These compromised accounts are then used to send malicious links to high-ranking employees of major companies, effectively leveraging existing trust to bypass initial security measures. The initial lure often takes the form of a Calendly meeting invitation, a common tool for scheduling professional interactions, further enhancing its deceptive appeal.
Upon clicking the Calendly link, the victim is directed to a meticulously crafted phishing page that impersonates a legitimate Zoom or Microsoft Teams meeting login. This page is designed to look indistinguishable from the real service, often employing typosquatted domains that are visually similar to authentic URLs. For instance, domains like "us.zoom.06webin.us" are employed, exploiting the human tendency to overlook subtle discrepancies in complex URLs. Once on the phishing page, users are prompted to enter their name and, crucially, grant permissions for webcam access.

This webcam access is not for a genuine meeting but serves as a critical component of the attack. The live webcam feed is stealthily transmitted to the attackers’ control panel using mediasoup WebRTC technology. This allows the threat actors to observe their targets in real-time, gathering valuable information and assessing their potential.
The Deceptive "Solo" Meeting and Deepfake Deception
Following the webcam access, the victim is presented with a seemingly innocuous "Zoom call" where they appear to be alone, with a message indicating they are "waiting for other participants." This is where the attack takes a deeply sophisticated turn. The "other participants" the victim is waiting for are not real individuals but pre-recorded, AI-generated video segments. These videos feature deepfake headshots, created using tools like OpenAI’s ChatGPT, superimposed onto authentic body movements captured during previous, legitimate meetings.
"So, each successful attack feeds source material into the composites used against the next target," JUMPSEC explains. "This combined with the Telegram account takeover method means that the fake meeting shows a plausibly familiar-looking face, moving with the body language of someone who was actually captured on camera." This ingenious use of deepfakes and pre-recorded footage creates a highly convincing illusion, making it exceptionally difficult for the victim to discern that they are not participating in a genuine interaction.
During this staged meeting, the operator, controlling a sophisticated panel, can manipulate the session. They can send fake messages, such as "your mic isn’t working," to further disorient the victim. The ultimate goal is to trigger a "Zoom SDK Update" or a similar pretext, which, when executed by the unsuspecting user, delivers the final ClickFix payload.
Cryptocurrency Wallet Reconnaissance and Selective Targeting
A particularly alarming aspect of the BlueNoroff ClickFix operation is its pre-attack wallet reconnaissance. Before the malware is even delivered, the phishing kit executes a fingerprinting process on the victim’s web browser. This step aims to identify and inventory any cryptocurrency wallets installed on the system. This capability allows the attackers to move beyond a generic malware distribution and engage in highly targeted attacks. By knowing the victim’s cryptocurrency holdings, BlueNoroff can prioritize and selectively target individuals with high-value wallets, maximizing their potential return on investment.

This selective targeting is a hallmark of advanced persistent threats (APTs) and indicates a significant evolution in BlueNoroff’s operational capabilities. It transforms a broad phishing campaign into a precision strike, focusing resources on individuals most likely to yield substantial illicit gains.
Operational Infrastructure and Active Development
The cybersecurity researchers have identified an active and evolving threat actor infrastructure. Analysis of the phishing kit has revealed at least five distinct versions deployed between May 31 and July 14, 2026. This rapid iteration suggests continuous development, fine-tuning, and adaptation by the threat actors to evade detection and improve their attack efficacy.
Furthermore, the exfiltration function within the Telegram malware component hard-codes the bot token and chat ID. Querying the Telegram API with this information has led researchers to identify an operator associated with the username "John" (@alchemy_john_mac). Evidence suggests that as recently as May 2026, this individual was actively engaging with cryptocurrency group administrators, inquiring about vesting contracts and fund withdrawals, further solidifying the link between this operator and the financially motivated cybercriminal activities.
The Strategic Choice of Zoom and Teams
The consistent focus on Zoom and Microsoft Teams, to the exclusion of platforms like Google Meet, is a deliberate strategic choice by the threat actors. Sean Moran, Head of Threat Research and Enablement at JUMPSEC, outlines three key reasons for this preference:
- ClickFix Pretext Compatibility: The "Zoom/Teams SDK out of date" lure is most effective on platforms that users perceive as having robust desktop clients. Both Zoom and Teams fit this description, with their complex client-side functionalities. Google Meet, being primarily browser-based, does not offer a similar pretext for an "update" that would trigger user action.
- Target-Application Fit: Zoom and Microsoft Teams have become the de facto communication standards for many in the cryptocurrency, venture capital, and founder communities. These platforms are often used for high-stakes investor and partnership discussions. Google Meet, while widely used, is often perceived more as a general customer interaction tool, making it a less attractive target for attackers seeking to infiltrate high-value financial discussions.
- Typosquatting Surface: The domain naming conventions of Zoom and Teams offer a more fertile ground for typosquatting. URLs like "us.zoom.06webin.us" are easily crafted to resemble legitimate Zoom links, complete with subdomains, making them difficult for the average user to distinguish. In contrast, the simpler and more standardized "meet.google.com" domain is significantly harder to spoof effectively through typosquatting.
While the current ClickFix kit primarily features Zoom and Teams lures, JUMPSEC notes that the source code includes an unimplemented "stub" for a Google Meet equivalent. This suggests that while not currently active, the capability could be developed and deployed if the threat actors deem it strategically advantageous.

Broader Implications for Cybersecurity
The BlueNoroff ClickFix campaigns underscore a critical shift in the threat landscape. As the Web3 ecosystem and digital asset markets continue to mature, threat actors are increasingly recognizing that compromising individuals who control access to these assets can be as lucrative, if not more so, than attacking the underlying infrastructure. The sophistication of these attacks, blending technical prowess with deep psychological manipulation, highlights the evolving nature of cybercrime.
The BlueNoroff group’s continuous refinement of their tactics, techniques, and procedures demonstrates a commitment to staying ahead of security measures. This persistent innovation necessitates a proactive and adaptive security posture from organizations. The implications extend far beyond technical defenses, emphasizing the need to consider identity, human relationships, and communication channels as integral components of a robust security strategy.
In conclusion, the ClickFix operation represents a significant advancement in North Korean cyber capabilities, showcasing a mature understanding of social engineering, technological exploitation, and financial motivations. The targeting of trusted communication platforms, coupled with deepfake technology and cryptocurrency wallet reconnaissance, presents a formidable challenge to individuals and organizations operating in the digital asset space. A comprehensive approach to cybersecurity, encompassing technical safeguards, user education, and a keen awareness of evolving threat vectors, is paramount in mitigating the risks posed by such sophisticated and persistent adversaries.







