BlueNoroff Hijacks Telegram Accounts to Deliver ClickFix Malware
Key Takeaways North Korean threat actor BlueNoroff is hijacking legitimate Telegram accounts of industry contacts. The compromised accounts are used to target senior staff at cryptocurrency and Web3...
Key Takeaways
- North Korean threat actor BlueNoroff is hijacking legitimate Telegram accounts of industry contacts.
- The compromised accounts are used to target senior staff at cryptocurrency and Web3 firms with fake Zoom and Microsoft Teams meeting links.
- The campaign, dubbed ClickFix, aims to steal cryptocurrency and credentials by deploying sophisticated malware after profiling victims’ browsers for crypto wallets.
- The attack chain involves social engineering, fake video calls, and a malicious “fix” that tricks users into executing harmful commands.
- Organizations in the Web3 and crypto sectors must exercise extreme caution and verify meeting invitations through alternative communication channels.
BlueNoroff Leverages Compromised Telegram Accounts in Sophisticated ClickFix Campaign
A North Korean state-sponsored hacking collective, BlueNoroff, has significantly advanced its social engineering tactics, now exploiting trusted Telegram accounts to distribute malware. This group, an integral part of the larger Lazarus Group ecosystem, is actively compromising the Telegram profiles of legitimate industry professionals to launch targeted attacks.
Table Of Content
These hijacked accounts then send fraudulent invitations for Zoom and Microsoft Teams meetings to high-ranking personnel within cryptocurrency and Web3 organizations. The primary objective is financial gain, with operators systematically scanning victims’ browsers for cryptocurrency wallets before deploying their custom malware, ultimately seeking to exfiltrate credentials and digital assets to fund state operations.
This operation transcends typical phishing, functioning as a self-propagating pipeline that expands its reach with each new compromised contact. Security analysts at Jumpsec uncovered the intricate details of this campaign after identifying exposed JavaScript source maps on the attackers’ live infrastructure.
Jumpsec said in a report that the attacker’s toolkit effectively impersonates legitimate Zoom and Teams meeting interfaces while covertly profiling victims for cryptocurrency wallets and manipulating them into executing a malicious “ClickFix” command.
The research team successfully reconstructed both Windows and macOS attack paths, from the initial lure to the final stages of data exfiltration. A critical element of this campaign is its reliance on established trust; victims receive malicious links from individuals they know and may have previously interacted with in person. This renders conventional advice to “check the sender” ineffective, as the account itself is genuine, only its controller has changed. This pattern mirrors other recent BlueNoroff campaigns that have employed fake meeting pages to target cryptocurrency professionals.
The impact of a successful compromise extends broadly. Any infected machine with an active Telegram session risks having its session hijacked, perpetuating a cycle that continuously ensnares new targets. Firms managing substantial digital assets remain prime targets, as a single successful breach can yield significant illicit gains.
Exploiting Trust: The Blueprint of BlueNoroff’s Telegram Hijacks
In cases analyzed by Jumpsec, compromised Telegram accounts belonging to real contacts were used to message senior employees at prominent companies. These interactions often begin with what appears to be an ordinary meeting invitation. The malicious links are carefully crafted, incorporating familiar labels like “us.zoom” into attacker-controlled domains, creating a deceptive sense of security.
Upon clicking the link, victims are prompted to enter a name and grant camera access. Unbeknownst to them, their webcam feed is silently transmitted to the operator’s control panel. Victims are then placed in a simulated waiting room, while the attacker joins the “meeting” with a staged video, often constructed from AI-generated headshots combined with real body motion to enhance credibility.
During the fake call, timed chat messages falsely claim microphone issues and prompt the victim to install a bogus Zoom SDK update. This leads to the “ClickFix” prompt, where the victim is instructed to copy what appears to be a simple fix. However, the clipboard content is surreptitiously replaced with a harmful command. This social engineering technique builds upon the broader ClickFix lure strategy observed in other malware campaigns.
Crucially, before any payload is delivered, the attack kit meticulously scans the victim’s browser for cryptocurrency wallet extensions, such as MetaMask, and related digital asset objects. These reconnaissance results are sent to the operator panel, ensuring that only high-value targets proceed through the full attack chain. While the Zoom and Teams builds share a common core module, the presence of a Google Meet string in the code suggests the potential existence of a third lure. This persistent focus on decentralized finance (DeFi) trust and chat-based delivery is a recurring theme in Lazarus Group’s cryptocurrency-focused operations.
What You Should Do
- Verify All Meeting Invitations: If you receive a Zoom, Teams, or Google Meet invitation via Telegram, especially from someone you know, independently verify the meeting details through a separate communication channel (e.g., a phone call, email to a known address, or an alternative messaging app). Do not rely solely on the Telegram message.
- Scrutinize URLs: Always examine the full domain of any link before clicking. Do not be fooled by legitimate-sounding subdomains (e.g., “us.zoom”) if the main domain is unfamiliar or suspicious. Real meeting tools will never ask you to paste terminal commands to resolve audio or camera issues.
- Be Wary of Unexpected Requests: Be highly suspicious of any requests to download “updates,” “SDKs,” or execute commands from your clipboard, particularly during a meeting setup or troubleshooting.
- Implement Multi-Factor Authentication (MFA): Enable MFA on all your online accounts, especially for Telegram, cryptocurrency exchanges, and corporate services, to add an extra layer of security against account hijacking.
- Educate Employees: Conduct regular cybersecurity awareness training, emphasizing the sophisticated social engineering tactics employed by groups like BlueNoroff, particularly for employees in high-value roles or those handling digital assets.
- Monitor for Indicators of Compromise (IoCs): Security teams should actively monitor their networks for the provided IoCs (SHA256 hashes, domains, and IP addresses) and block them at the perimeter.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.