BlueNoroff, a financially motivated North Korean threat group linked to the Lazarus ecosystem, is using compromised Telegram accounts and fake video meetings to target Web3 and cryptocurrency organizations.
The campaign turns breached victims into new delivery channels, creating a repeating attack chain built on trusted relationships.
Researchers at JUMPSEC obtained exposed source maps for an active phishing kit that impersonates Zoom and Microsoft Teams.
The source-level visibility revealed a full victim-acquisition platform combining Telegram account abuse, wallet discovery, deepfake-style meeting lures, ClickFix social engineering, and malware delivery for Windows and macOS.
The operation is especially dangerous because its initial messages come from legitimate Telegram accounts belonging to real industry contacts.
In observed cases, targets had met the contact in person or already trusted them, making standard sender-verification advice less effective.
BlueNoroff’s Telegram Meeting Trap
The attackers first compromise a Telegram account and wait for an opportunity to contact people in that victim’s professional network.
They then send a link resembling a Zoom or Teams meeting invitation, using typosquatted domains designed to look convincing at a glance.
After a target opens the link, the phishing page asks for a username and webcam access, imitating the normal steps of joining a video call.

The captured webcam stream can be sent to an operator-controlled panel through WebRTC, while the victim is placed in a fake meeting lobby.
An operator can join the staged call using pre-recorded video, including AI-generated faces placed over body movements captured during previous meetings.
This approach creates the appearance of a familiar participant while avoiding a live conversation.
The fake participant claims there is an audio problem and tells the victim that a Zoom or Teams SDK update is required.
A false update dialog then instructs the target to copy and run a command, but the page silently replaces the displayed text with a malicious ClickFix payload.
On Windows, the copied ClickFix command launches a compact PowerShell loader that retrieves a VBScript implant from attacker-controlled infrastructure.
The loader adds a Microsoft Defender exclusion, restarts Defender to apply it, and executes the downloaded script with separate arguments to support distinct beaconing functions.

One recovered VBScript implant was identified by security engines as Trojan.NukeSped, a malware family previously associated with Lazarus activity.
The implant collects host, operating system, processor, network, process, browser-extension, and user information before receiving commands from its command-and-control server.
Notably, one version checks browser profile directories for Telegram Web IndexedDB data across Chrome, Edge, Brave, and Firefox.
A victim with active Telegram usage can therefore become a potential source of a stolen session that attackers may reuse to message new contacts.
That capability is central to the self-propagating model. JUMPSEC found that two of three analyzed cases were used to contact additional people, while the broader technique overlaps with BlueNoroff’s previously documented GhostCall-style propagation methods.
Indicators of Compromise
| Type | SHA-256 | Description |
|---|---|---|
| PowerShell loader | 7a0b96f1063593a2e76f2f92ddfe091776a2ba63bc4f87f83dc5ebb675309d8d | Zoom-themed loader |
| PowerShell loader | 180f797723bd65e82189eb1f737d39ce522614a182e2b46b51faeb49953a412f | weekly-up.online loader |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.