BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector

2026-04-27 Arctic Wolf

https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/

Thumbnail for BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector

Arctic Wolf attributes a targeted intrusion against a North American Web3 and cryptocurrency company with high confidence to BlueNoroff, a financially motivated Lazarus Group subgroup. The attack began with spear-phishing that impersonated a Fintech legal figure and used a manipulated Calendly invite containing a typo-squatted Zoom link. The fake meeting page exfiltrated live camera footage for reuse in later lures and launched a ClickFix-style clipboard injection that led to credential extraction from the victim’s device, browsers, and cryptocurrency wallet extensions. The Windows-focused chain included a PowerShell-based C2 implant, an AES-encrypted browser injection payload, and Telegram Bot API screenshot exfiltration. Infrastructure analysis found more than 80 typo-squatted Zoom and Teams domains and over 100 additional targets, mostly in cryptocurrency, blockchain finance, investment, executive, and founder roles.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 17158cd6490a2b3c672d087f3d69107… 2026-04-27 2026-04-27
HASH 6030338469819129924c6e01e110145… 2026-04-27 2026-04-27
HASH db446f0e1d18b43805bfefe1af934ae… 2026-04-27 2026-04-27
HASH dd1c72823f933952619cbb86aaeaea4… 2026-04-27 2026-04-27
HASH a37cb38b178833f15bf13fd5fa622b6… 2026-04-27 2026-04-27
HASH edd0301ffb793169b1314c59c0ef3a9… 2026-04-27 2026-04-27
URL http://check02id.com:7365/hello 2026-04-27 2026-04-27
URL https://uu03webzoom.us/develope… 2026-04-27 2026-04-27
URL https://uu03webzoom.us/j/896979… 2026-04-27 2026-04-27
DOMAIN thriddata.com 2026-04-27 2026-04-27
DOMAIN teams-live.org 2026-04-27 2026-04-27
DOMAIN uu03webzoom.us 2026-04-27 2026-04-27
DOMAIN support.teams-live.org 2026-04-27 2026-04-27
DOMAIN nubit.teams-live.org 2026-04-27 2026-04-27
DOMAIN check02id.com 2026-04-16 2026-04-27
IPv4 83.136.209.22 2026-04-16 2026-04-27
IPv4 83.136.208.246 2026-04-16 2026-04-27
IPv4 104.145.210.107 2026-04-16 2026-04-27
IPv4 188.227.197.32 2026-04-08 2026-04-27
DOMAIN ms-live.com 2025-12-04 2026-04-27
DOMAIN web01zoom.com 2025-06-20 2026-04-27

Related Actors

Related Reports

« Back