BlueNoroff Uses Compromised Telegram Contacts and Fake Meetings to Build a Self-Propagating Attack Chain

BlueNoroff, a financially motivated North Korean threat group linked to the Lazarus ecosystem, is using compromised Telegram accounts and fake video meetings to target Web3 and cryptocurrency organizations.

The campaign turns breached victims into new delivery channels, creating a repeating attack chain built on trusted relationships.

Researchers at JUMPSEC obtained exposed source maps for an active phishing kit that impersonates Zoom and Microsoft Teams.

The source-level visibility revealed a full victim-acquisition platform combining Telegram account abuse, wallet discovery, deepfake-style meeting lures, ClickFix social engineering, and malware delivery for Windows and macOS.

The operation is especially dangerous because its initial messages come from legitimate Telegram accounts belonging to real industry contacts.

In observed cases, targets had met the contact in person or already trusted them, making standard sender-verification advice less effective.

BlueNoroff’s Telegram Meeting Trap

The attackers first compromise a Telegram account and wait for an opportunity to contact people in that victim’s professional network.

They then send a link resembling a Zoom or Teams meeting invitation, using typosquatted domains designed to look convincing at a glance.

After a target opens the link, the phishing page asks for a username and webcam access, imitating the normal steps of joining a video call.

A founder announcing their Telegram account as compromised (Source: jumpsec)
A founder announcing their Telegram account as compromised (Source: jumpsec)

The captured webcam stream can be sent to an operator-controlled panel through WebRTC, while the victim is placed in a fake meeting lobby.

An operator can join the staged call using pre-recorded video, including AI-generated faces placed over body movements captured during previous meetings.

This approach creates the appearance of a familiar participant while avoiding a live conversation.

The fake participant claims there is an audio problem and tells the victim that a Zoom or Teams SDK update is required.

A false update dialog then instructs the target to copy and run a command, but the page silently replaces the displayed text with a malicious ClickFix payload.

On Windows, the copied ClickFix command launches a compact PowerShell loader that retrieves a VBScript implant from attacker-controlled infrastructure.

The loader adds a Microsoft Defender exclusion, restarts Defender to apply it, and executes the downloaded script with separate arguments to support distinct beaconing functions.

OBS Virtual Cam for demo purposes (Source: jumpsec)
OBS Virtual Cam for demo purposes (Source: jumpsec)

One recovered VBScript implant was identified by security engines as Trojan.NukeSped, a malware family previously associated with Lazarus activity.

The implant collects host, operating system, processor, network, process, browser-extension, and user information before receiving commands from its command-and-control server.

Notably, one version checks browser profile directories for Telegram Web IndexedDB data across Chrome, Edge, Brave, and Firefox.

A victim with active Telegram usage can therefore become a potential source of a stolen session that attackers may reuse to message new contacts.

That capability is central to the self-propagating model. JUMPSEC found that two of three analyzed cases were used to contact additional people, while the broader technique overlaps with BlueNoroff’s previously documented GhostCall-style propagation methods.

Indicators of Compromise

TypeSHA-256Description
PowerShell loader7a0b96f1063593a2e76f2f92ddfe091776a2ba63bc4f87f83dc5ebb675309d8dZoom-themed loader
PowerShell loader180f797723bd65e82189eb1f737d39ce522614a182e2b46b51faeb49953a412fweekly-up.online loader

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories