BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector
2026-04-27 • Arctic Wolf •
Arctic Wolf attributes a targeted intrusion against a North American Web3 and cryptocurrency company with high confidence to BlueNoroff, a financially motivated Lazarus Group subgroup. The attack began with spear-phishing that impersonated a Fintech legal figure and used a manipulated Calendly invite containing a typo-squatted Zoom link. The fake meeting page exfiltrated live camera footage for reuse in later lures and launched a ClickFix-style clipboard injection that led to credential extraction from the victim’s device, browsers, and cryptocurrency wallet extensions. The Windows-focused chain included a PowerShell-based C2 implant, an AES-encrypted browser injection payload, and Telegram Bot API screenshot exfiltration. Infrastructure analysis found more than 80 typo-squatted Zoom and Teams domains and over 100 additional targets, mostly in cryptocurrency, blockchain finance, investment, executive, and founder roles.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 17158cd6490a2b3c672d087f3d69107… | 2026-04-27 | 2026-04-27 |
| HASH | 6030338469819129924c6e01e110145… | 2026-04-27 | 2026-04-27 |
| HASH | db446f0e1d18b43805bfefe1af934ae… | 2026-04-27 | 2026-04-27 |
| HASH | dd1c72823f933952619cbb86aaeaea4… | 2026-04-27 | 2026-04-27 |
| HASH | a37cb38b178833f15bf13fd5fa622b6… | 2026-04-27 | 2026-04-27 |
| HASH | edd0301ffb793169b1314c59c0ef3a9… | 2026-04-27 | 2026-04-27 |
| URL | http://check02id.com:7365/hello | 2026-04-27 | 2026-04-27 |
| URL | https://uu03webzoom.us/develope… | 2026-04-27 | 2026-04-27 |
| URL | https://uu03webzoom.us/j/896979… | 2026-04-27 | 2026-04-27 |
| DOMAIN | thriddata.com | 2026-04-27 | 2026-04-27 |
| DOMAIN | teams-live.org | 2026-04-27 | 2026-04-27 |
| DOMAIN | uu03webzoom.us | 2026-04-27 | 2026-04-27 |
| DOMAIN | support.teams-live.org | 2026-04-27 | 2026-04-27 |
| DOMAIN | nubit.teams-live.org | 2026-04-27 | 2026-04-27 |
| DOMAIN | check02id.com | 2026-04-16 | 2026-04-27 |
| IPv4 | 83.136.209.22 | 2026-04-16 | 2026-04-27 |
| IPv4 | 83.136.208.246 | 2026-04-16 | 2026-04-27 |
| IPv4 | 104.145.210.107 | 2026-04-16 | 2026-04-27 |
| IPv4 | 188.227.197.32 | 2026-04-08 | 2026-04-27 |
| DOMAIN | ms-live.com | 2025-12-04 | 2026-04-27 |
| DOMAIN | web01zoom.com | 2025-06-20 | 2026-04-27 |