The images in this article were generated with artificial intelligence. How we publish
A new report on the campaigns attributed to North Korean actors (the activity known by firms such as BlueNoroff / ClickFix / ClickFake) reveals a remarkable transformation: it is not just a matter of isolated posts or links, but an operational platform that combines social engineering, confidence supplanting and malware delivery in a repetitive victim collection pipe.
The campaign takes advantage of legitimate Telegram accounts, real meetings and false calendars to push the victim to a false meeting; the Calendly link redirects to typosquat domains that look like Zoom / Teams URLs. When the victim grants camera permissions, the video does not go to Zoom but to a panel of the attacker using WebRTC mediasup, and the meeting is controlled with messages that induce an "SDK update" that installs the ClickFix charger.

There are two features that raise it over a classic phishing. First, automation to identify high-value targets by fingerprinting browser extensions (looking for MetaMask-type portfolios) and checking Telegram Web sessions to appropriate accounts. Second, the use of previous material to generate video compositions with synthetic faces - according to research, headshots generated with IA are used on actual movements captured in previous meetings - making the supplanting much more credible for contacts that already know the victim.
The implications are strategic: The attackers monetize personal relationships and trust rather than pure technical vulnerabilities. In the Web3 ecosystem, where private keys and browser sessions are access to real value, compromise individuals with privileges or access often is worth more than breaking infrastructure. In addition, Telegram's accounting technique creates a multiplier effect: a kidnapped account serves to launch new campaigns directed against the victim's network.
The detected kit is in active development (multiple versions detected between the end of May and July 2026) and covers Windows and macOS with different infection chains: in Windows it abuses PowerShell and VBScript to disable and exclude folders from Defend, scan browser profiles and detect portfolio extensions; in macOS it delivers false installers that exfilter data through a Telegram bot with embedded token. This practice of encoding tokens facilitates traceability, but does not prevent damage when the bot is already operational.
What users and security equipment should do now: validate the source of Telegram calendar invitations and messages even when they come from known contacts; distrust requests that ask to run updates from pages that mimic Zoom / Teams; keep web messaging sessions closed when not used and review authorized devices in Telegram; use hardware portfolios for private keys and separate the browser for critical operations from the general browser; impose execution control policies (AppLocker / SMB file, unauthorised scripts lock) and monitor changes in antivirus exclusions or endpoint security services.
For detection and response equipment, it is appropriate to implement the monitoring of atypical indicators: creation of exclusions in Defender, unusual connections to typosquat domains (patterns with subdomains that mimic zoom / teams), outgoing WebRTC traffic to non-corporate infrastructures and use of Telegram bots for exfiltration. It is also critical to deploy phishing-resistant authentication mechanisms (FIDO2 / WebAuthn) and to segment environments that host portfolio extensions or keys stored in the browser.

Platformer operators should strengthen reporting processes and quickly suspend malicious domains and bots, and video conference providers should study signals that allow for the differentiation of legitimate meetings from pages requesting camera permits outside their normal flows. Reports such as JUMPSEC show that technical prevention must be accompanied by identity and relationship controls: security today is both social and technical.
If you are responsible for an organization with exposure to cryptomonedas, investors or founders, consider concrete measures: third-party access audits, awareness-raising sessions focused on attacks by supplanting known contacts, and periodic reviews of public profiles that the opponent can use to build deepfakes. Reporting incidents to the affected platforms and authorities also helps to stop the expansion of malicious infrastructure.
The full research and follow-up of these campaigns can be found in the public resources of the analysts who have documented the activity; for general context and additional technical analysis visit JUMPSEC and the specialized coverage of The Hacker News. These threats evolve rapidly: the combination of session control, strengthening of authentication and rigid separation of critical environments is the most practical defense today.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...