BlueNoroff ClickFix Kit Threat Investigation Report
2026-07-24 • Jumpsec •
https://www.jumpsec.com/bluenoroff-clickfix-kit-threat-investigation-report/
BlueNoroff used compromised Telegram accounts belonging to trusted industry contacts to direct cryptocurrency and Web3 personnel into operator-controlled Zoom and Microsoft Teams lures. The kit profiled browser wallets, relayed victims' webcams, displayed prepared participant videos, and triggered ClickFix commands that installed Windows or macOS malware. Exposed source maps revealed the complete web application logic, while the Windows chain delivered a VBScript implant identified as NukeSped and the macOS chain used fake meeting installers to conceal a Mach-O stealer. JUMPSEC observed the compromise-and-reuse of Telegram sessions as a repeatable propagation mechanism and found associated infrastructure still active on July 22, 2026.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | googie.us-gmeet.com | 2026-07-24 | 2026-07-24 |
| URL | https://us.zoom.06webin.us/j/98… | 2026-07-24 | 2026-07-24 |
| DOMAIN | weekly-up.online | 2026-07-24 | 2026-07-24 |
| DOMAIN | 06webin.us | 2026-07-24 | 2026-07-24 |
| DOMAIN | callsdk.online | 2026-07-24 | 2026-07-24 |
| HASH | b149e207a3aad68605785710c58e843… | 2026-07-24 | 2026-07-24 |
| DOMAIN | zoom.05ukweb.uk | 2026-04-14 | 2026-07-24 |