SOC Prime Bias: Критичний

29 Apr 2026 14:34 UTC

BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector

Author Photo
SOC Prime Team linkedin icon Follow
BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

BlueNoroff, a financially motivated subgroup of the DPRK-linked Lazarus Group, carried out a targeted intrusion against a North American Web3 and cryptocurrency company. The attackers combined ClickFix techniques, fileless PowerShell execution, and AI-generated fake Zoom meeting invitations to secure initial access and expand their reach within the environment. The operation highlights a mature blend of social engineering and living-off-the-land tactics designed to support cryptocurrency theft.

Investigation

Arctic Wolf analysts detected the intrusion after identifying unusual PowerShell activity and malicious Zoom meeting links enhanced with AI-generated content. Additional evidence pointed to ClickFix delivery methods and fileless execution, indicating a clear attempt to evade conventional antivirus defenses. Attribution to BlueNoroff was based on the observed tooling, operational behavior, and tradecraft patterns long associated with Lazarus Group activity.

Mitigation

Organizations should require multi-factor authentication for Zoom and other conferencing platforms, limit unnecessary PowerShell remoting, and monitor closely for suspicious ClickFix-related binaries. Email security controls should also be strengthened to catch AI-generated phishing lures, while users should be trained to verify unexpected meeting invitations before interacting with them.

Response

If this activity is detected, isolate the affected endpoints immediately, capture volatile memory, and conduct forensic analysis of PowerShell logs and any ClickFix-related artifacts. Compromised credentials should be revoked, sensitive secrets rotated, and incident response procedures for potential cryptocurrency theft activated. Relevant indicators should also be shared with industry ISACs, and detections should be updated to reflect the latest findings.

Attack Flow

We are still updating this part.

Detections

Download or Upload via Powershell (via cmdline)

SOC Prime Team
28 Apr 2026

Suspicious Powershell Strings (via cmdline)

SOC Prime Team
28 Apr 2026

Suspicious CURL Usage (via cmdline)

SOC Prime Team
28 Apr 2026

Suspicious Usage of Invoke-RestMethod (via powershell)

SOC Prime Team
28 Apr 2026

Suspicious Powershell Strings (via powershell)

SOC Prime Team
28 Apr 2026

Call Suspicious .NET Methods from Powershell (via powershell)

SOC Prime Team
28 Apr 2026

Call Suspicious Windows API Functions from Powershell (via powershell)

SOC Prime Team
28 Apr 2026

Possible Powershell Obfuscation Indicators (via powershell)

SOC Prime Team
28 Apr 2026

Suspicious Binary / Scripts in Autostart Location (via file_event)

SOC Prime Team
28 Apr 2026

Possible Telegram Abuse As Command And Control Channel (via dns_query)

SOC Prime Team
28 Apr 2026

Simulation

We are still updating this part.