
Fake Advisors, ClickFix, and Chrome Sync Spying
This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…
North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed cryptocurrency wallet extensions and selectively targets high-value victims before delivering malware.
The campaign, attributed to BlueNoroff, begins with a message from an account the target already trusts and has met in real life. That trust exists because the attackers hijacked a legitimate Telegram account rather than creating a new one. The message contains a Calendly link that appears to schedule a normal Zoom or Teams meeting.
Once the victim clicks through, they land on a domain that looks like Zoom or Teams but is actually a fake page impersonating the videoconferencing service. The page requests webcam permissions and streams video back to an operator panel before the meeting even starts. After the victim joins, they are shown a screen stating they are waiting for other participants, alone in the call.
At that point a human operator intervenes, sending a fake message claiming the microphone is not working and prompting a "Zoom SDK Update." Following that update triggers a ClickFix-style command that downloads a fake Zoom or Teams installer and delivers malware.
Several factors made this attack effective:
Treat meeting links as unverified even when they come from known contacts, and confirm unusual invites through a separate channel before joining. Never run commands or install updates mid-call to resolve audio or video issues; legitimate software updates do not work that way. Report unusual meeting invites or account behavior immediately, since a single compromised messenger account can be reused against its own contact list. Teams that manage digital assets should expect extra scrutiny and profiling attempts, and should apply added verification steps for meeting invites and in-call software prompts.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers hijack a trusted contact's Telegram account and send a Calendly link that leads to a lookalike Zoom or Teams domain rather than the real videoconferencing service.
The victim is left on a waiting screen, an operator sends a fake mic or audio problem message, and then prompts a 'Zoom SDK Update' that delivers the ClickFix malware payload.
The phishing kit fingerprints the victim's browser to inventory installed cryptocurrency wallet extensions, allowing attackers to selectively target higher-value victims before delivering malware.
If a victim runs the payload with Telegram open, their Telegram session can be stolen and reused to send the same lure to their own trusted contacts, creating a self-propagating chain.
Your colleague pings you on Telegram: “Hi, here’s my Calendly link to book our Zoom.” Looks normal, right? That link quietly redirects you to a fake Zoom page on a lookalike domain, asks for your webcam, and shows a “waiting for other participants” screen that feels like Zoom but runs entirely in the browser. Behind that page, BlueNoroff operators watch your webcam feed, fingerprint your browser for crypto wallet extensions, then push a fake “Zoom SDK Update” pop-up that actually installs their ClickFix malware. If any meeting ever tells you to install a Zoom or Teams “SDK update” to fix audio or video, stop immediately and call IT or your contact using a separate channel before you click anything.

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…