BlueNoroff ClickFix Kit Threat Investigation Report

2026-07-24 Jumpsec

https://www.jumpsec.com/bluenoroff-clickfix-kit-threat-investigation-report/

Thumbnail for BlueNoroff ClickFix Kit Threat Investigation Report

BlueNoroff used compromised Telegram accounts belonging to trusted industry contacts to direct cryptocurrency and Web3 personnel into operator-controlled Zoom and Microsoft Teams lures. The kit profiled browser wallets, relayed victims' webcams, displayed prepared participant videos, and triggered ClickFix commands that installed Windows or macOS malware. Exposed source maps revealed the complete web application logic, while the Windows chain delivered a VBScript implant identified as NukeSped and the macOS chain used fake meeting installers to conceal a Mach-O stealer. JUMPSEC observed the compromise-and-reuse of Telegram sessions as a repeatable propagation mechanism and found associated infrastructure still active on July 22, 2026.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN googie.us-gmeet.com 2026-07-24 2026-07-24
URL https://us.zoom.06webin.us/j/98… 2026-07-24 2026-07-24
DOMAIN weekly-up.online 2026-07-24 2026-07-24
DOMAIN 06webin.us 2026-07-24 2026-07-24
DOMAIN callsdk.online 2026-07-24 2026-07-24
HASH b149e207a3aad68605785710c58e843… 2026-07-24 2026-07-24
DOMAIN zoom.05ukweb.uk 2026-04-14 2026-07-24

Related Actors

Related Reports

« Back