LW30: ClickFix meetings, groupware compromise, and IT worker revenue
Executive Summary
Fake meetings and job interviews drove several DPRK-linked operations last week. BlueNoroff, Sapphire Sleet, and Famous Chollima used compromised contacts or recruiter personas to direct targets to imitation meeting pages, then persuaded Windows and macOS users to execute commands. The resulting malware targeted browser credentials, cryptocurrency wallets, and remote control of the host.
Kimsuky reporting covered compromise at a South Korean groupware developer and movement into customer environments. Related presentations added victim counts and contrasted spearphishing with watering-hole exploitation. IT worker reporting followed both the hiring risk and the flow of salaries into a centralized state-linked payment system. An initial AFX account documented a bridge theft through developer compromise without making the later, more specific attribution published the following week.
Key Trends
1. Fake meetings turned trusted conversations into execution
JUMPSEC documented a BlueNoroff platform that used stolen Telegram accounts to approach cryptocurrency targets, profile their browsers, relay webcam feeds, and present fake Zoom or Teams meetings. Windows targets received a VBScript implant identified as NukeSped, while the macOS chain used a fake installer to conceal a Mach-O stealer.12
The ORO intrusion also began with a compromised Telegram contact and a fake Teams meeting. After an employee ran AppleScript, the attacker installed a browser extension and persistent implant, then stole the wallet controlling Bittensor SN15 and sold 147,000 Alpha Tokens. ORO attributed the operation to Sapphire Sleet from infrastructure and payload overlap with Microsoft reporting.3
Famous Chollima used fake cryptocurrency and Web3 interviews to deliver PylangGhost on Windows and GolangGhost plus a SwiftUI credential stealer on macOS. Invitation gating, browser fingerprinting, countdown pressure, and camera-error prompts increased pressure while limiting casual inspection.4
2. Groupware compromise reached downstream customers
ENKI reported that Kimsuky exploited a mail-server vulnerability at a South Korean groupware developer and likely used spearphishing in some cases. The attackers stole internal data and credentials, modified a login page to capture customer credentials, and deployed BirdTroy and DriveTroy. The Go-based backdoors used HTTP/3 and Google Drive for command and control.56
A conference presentation on the same activity added that at least four customers were compromised through one vendor’s product and five more victim servers were identified through infrastructure tracking. It also documented Gomir, HttpTroy, HelloDoor, reverse proxying, and movement into deployment and development systems.7
3. LNK files and watering holes covered different access paths
Kimsuky lures impersonating diplomatic personnel used malicious LNK files to install PebbleDash and PrxClient, create persistence, and relay traffic to RDP.8 AhnLab’s English and Korean June reviews documented broader work-themed LNK and spearphishing chains using PowerShell, AutoIt, HTA, scheduled tasks, DLL side-loading, and Python.910 A game-character design lure followed a similar shortcut-to-script pattern and ended with MoonPeak, a XenoRAT-based implant.11
A separate presentation contrasted targeted spearphishing with watering holes that exploit vulnerable South Korean Non-ActiveX security software. The demonstrated chains used public cloud and code-hosting services during delivery and control, then performed discovery, anti-analysis checks, in-memory execution, and remote command handling.12
4. IT worker operations combined access and revenue
Remote workers used stolen or fabricated identities, AI-generated application material, manipulated video, and laptop farms to enter Western companies. Reported outcomes included malware installation after onboarding, source-code theft, extortion, and possible supply-chain access.13
Records from an exposed DPRK payment server contained 390 accounts, chats, and cryptocurrency transactions. Workers sent salary payments through luckyguys.site to an administrator account, after which funds were pooled through structures associated with Unit 1020, Command 710, and a wallet assessed as likely tied to sanctioned Korea Ryonbong General Corporation.14
5. Cryptocurrency theft and naming changes needed careful context
AFX’s first incident account said a malicious repository shared over Telegram compromised a developer, after which the attacker persisted in JFrog and moved toward validator infrastructure. A remote payload enabled unauthorized access to the custody bridge. The report said neither Arbitrum nor its native bridge was compromised and did not yet make the UNC4899 attribution that appeared in the following week’s detailed post-mortem.15
Daily NK’s account of former military intelligence personnel stealing from North Korean banks described domestic crime using state-developed skills, not a state-directed external operation.16 Google also announced that DPRK-attributed clusters would use NEPTUNE as the second word in its unified naming system, while retaining old names and aliases for search.17
What to Watch
Block meeting or interview workflows that instruct users to run Terminal, PowerShell, or AppleScript commands. Verify unexpected requests through a separate channel even when they come from a known account. Groupware operators should review mail-server exposure, login-page integrity, vendor access, and unusual use of Google Drive or tunneling services from servers.
Reports Reviewed
DPRK’s Famous Chollima Deploys RATs Through ClickFake Job Interviews ↩︎
Analysis of Kimsuky’s Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant ↩︎
June 2026 Threat Trend Report on APT Attacks (South Korea) ↩︎
North Korean IT Workers: How DPRK infiltrates remote hiring ↩︎
From Payroll to Pyongyang: The DPRK IT Worker Money Trail ↩︎
AFX Bridge Incident: What Happened, What We Learned, and What Comes Next ↩︎
North Korea busts elite hacking ring inside its own banks ↩︎