
You've been muted...permanently.
Dave Bittner: Hello, everyone, and welcome to the CyberWire's "Research Saturday." I'm Dave Bittner, and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems, and protecting ourselves in a rapidly-evolving cyberspace. Thanks for joining us. [ Music ]
Ismael Valenzuela: This began with what appeared to be a legitimate business meeting invitation. The victim received a Calendly invite that eventually directed them to a typo-squatted Zoom domain, hosting a fully-simulated fake meeting environment.
Dave Bittner: Hmm.
Ismael Valenzuela: Which is like one of the most interesting pieces about this research.
Dave Bittner: That's Ismael Valenzuela, VP of Labs, Threat Research and Intelligence at Arctic Wolf. The research we're discussing today is titled "BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target the Web3 Sector." [ Music ]
Ismael Valenzuela: Yeah, once the victim joined the meeting, the attackers then used, you know, some more like traditional social engineering to get the victim to install what looked like an update for Zoom, right, a Zoom SDK update. But in reality, there was the multistage infection chain including PowerShell, browser credential theft, telegram session theft, persistence, and even collecting screenshots.
Dave Bittner: Well, and before we dig into a lot of the details here, and the specifics, you have said with a fairly high degree of confidence that BlueNoroff is who you're attributing this to. What do we know about that group?
Ismael Valenzuela: Yeah, so this is a group that is associated to North Korea, or DPRK, Democratic People's Republic of Korea. And this is essentially the same playbooks that they have been using for quite some time, where the primary objective of their activities is essentially financial theft. And the fact that they're targeting cryptocurrency executives, exchange operators, blockchain wallet developers, this is very consistent with the playbook with -- for this group, BlueNoroff. And essentially what they want to do is to generate revenue to keep supporting the country's interests.
Dave Bittner: Well, let's walk through this step by step. I mean, you mentioned that this begins with a Calendly invite. Can you take us through the details of what the victim experiences here?
Ismael Valenzuela: Yeah, so the victim receives this invite, and instead of like going to the domain that they think that they're going, they use a typo-squatted Zoom domain. This is -- I like to call it like a custom domain or a look-alike domain that may look like legitimate, like something related to the day-to-day work, but they're essentially going to a domain that is controlled by the attackers. When they go to this Zoom call, what they get is into like a fake meeting, which is very, very interesting, because this meeting has content that is specifically tailored to the victim. So the attacker -- that shows that the attacker has been able to conduct detailed investigative work prior to set up every meeting, which is very, very interesting. At least one of the 100 targets that we identified beyond the primary victim that we investigated in this case has publicly-disclosed LinkedIn, that their identity was used by the threat actor to approach all the targets, showing that there's a kind of pipeline to lure more people into these attacks, as we document in the report. And when the victim would join the call, they would see videos, they would see personas that are related to their day-to-day job. So if they were in the crypto world, they would see relevant people from the crypto world. Some of this content would be straight out of YouTube, webinars, and other public resources. Some of this content would be stolen from the footage recorded from previous victims that would be incorporated into their library. At the time of this recording, I can tell you there's more than 1,000 videos in this library.
Dave Bittner: Hmm. Help me understand, I mean, this part of it, because it seems like a tremendous amount of effort to -- that goes into this particular campaign here. Were they using AI-generated images, were they, you know, cleverly using the stolen webcam footage, you know, are they looping things in the background? What are they doing?
Ismael Valenzuela: What we found is that they use a combination of different things, scraping public videos out there from YouTube or webinars, and also deepfakes that they have generated, along with actual footage recorded from victims that got infected. And then, you know, they would join this call. And you could how, you know, their faces look like a bit -- a little bit like confused. They're clicking on links, they're like trying to find out what's going on. And this is directly stolen out of their computers. As we explain in the report, they would use a specific API to enable the recording of the webcam and the microphone to gather this information from the victims.
Dave Bittner: That's interesting. I mean, how many of us join a Zoom meeting and that's exactly the first thing you're used to seeing are people just getting settled in and trying to make sure everything's working. So it all seems normal at first, I suppose.
Ismael Valenzuela: Yeah, absolutely. Absolutely. And we have evidence that the captured footage -- and just kind of like a production pipeline as professionals would do, the attacker actually processed it -- processed the video through Adobe Premiere Pro.
Dave Bittner: Hmm.
Ismael Valenzuela: And it's worth mentioning that at least one image was edited with Microsoft Paint. So I guess, you know, maybe they ran out of budget, I don't know.
Dave Bittner: Wow. [laughs] Good old-school.
Ismael Valenzuela: Right?
Dave Bittner: Right, right. So let's continue down the pathway here. I mean, I'm a victim and I've helped -- I've entered this Zoom meeting, even though it's not a real Zoom meeting. What happens next?
Ismael Valenzuela: Yes. So what happened next is that the victim would receive some communications that, "Oh, you know, maybe something is not right, we cannot hear you," or, "We cannot see you well." They would continue the social engineering by trying to convince the victim to install an update, right, for Zoom. And I'm saying, "Zoom," here, but I have to say, since the publication of our report, we've seen the attacker moving away from Zoom and using Microsoft Teams --
Dave Bittner: Hmm.
Ismael Valenzuela: -- Teams themed lures towards, you know, other organizations, including outside of crypto, now enterprise software business services. But that's kind of the idea, right, once they convince you that you are among peers or, you know, joining a webinar, a call with people that have -- that share same interests, they would ask you to execute something on your machine. That's where the PowerShell comes in, or you know, a binary. In some cases, this is not that different from a fake CAPTCHA and other social engineering attacks that we see on a regular basis where they convince you to just copy and paste some commands on your machine that are going to install the malicious implant. [ Music ]
Dave Bittner: We'll be right back. [ Music ] And your research points out that once they go down this path, it is minutes before they have the system fully compromised.
Ismael Valenzuela: That is correct. Once the attack -- once the machine is fully compromised, it could be like less than five minutes, the attacker is stealing the telegram sessions, the browser credentials, the webcam footage, the audio from the microphone, and then they use these compromised accounts, these identities, to approach other victims. So now that means that, you know, these messages coming to you through telegram or these invitations may come from people that you trust.
Dave Bittner: Hmm. Now, I'm on this Zoom call and they've convinced me to run this software, they've installed the malware. Are they keeping me on the line or are they -- am I being discarded and they move on to the next person?
Ismael Valenzuela: Well, I mean, based on the information that we have, we haven't like joined like these calls necessarily. We haven't seen like all of the analysis that comes out of the investigation. But according to the videos that we have seen, the victim would -- may have been connected for some time. But then, I mean, enough time for the attacker to be able to convince you to do something, to install something on your computer, right? Once they have the information, there's no need to keep you there for any longer. So you know, if a call disconnects, it's like, "Okay, something didn't work. What is going on?" But it doesn't really matter. At that point those events have been stolen. And as I said before, we have seen some victims in social media, LinkedIn, X, mentioning that, "Hey, my identity has been stolen and it has been used to approach other people in my network."
Dave Bittner: How did Arctic Wolf pivot from this initial intrusion that you investigated to identifying 100 additional targets?
Ismael Valenzuela: Well, so part of that is based on our amazing threat research team. I have to say that, you know, we track threat actors -- we have been doing this for a long time, and also based on our telemetry, the ability to pivot from endpoint data, which was the very first indication or signal that we got here, to the ability to pivot to, you know, other infrastructure, to pivot to network telemetry, cloud telemetry, from over 10,000 customers and a lot of the open-source intelligence that we gather out there, too.
Dave Bittner: Was there anything that stood out about the victims themselves in terms of who they were going after, any -- are there particular parts of the world or particular industries that they seem to be targeting?
Ismael Valenzuela: Yeah, that's an interesting one. About 45%, 50% of the victims were CEOs, CEOs and founders.
Dave Bittner: Hmm.
Ismael Valenzuela: About 70% were related to blockchain, you know, exchanges, but also venture capital, venture capital companies.
Dave Bittner: Hmm.
Ismael Valenzuela: The geographic spread was over 20 countries. So I mean, that tells us that this is a well-resourced operation, with language capabilities, cultural awareness to do social engineering across multiple regions. And some of the individuals that we have found that were victims of this were kind of like well-known. Some of them, you know, public figures, people in, you know, different industries that have a high profile.
Dave Bittner: It's a good reminder that these sorts of things can happen to anyone.
Ismael Valenzuela: Absolutely. In terms of countries, the majority were focused on the United States, but we also found Singapore, United Kingdom, so -- and we're seeing since the publication of our research that they're expanding to other geographies and other businesses, too.
Dave Bittner: In terms of the attribution, what can you share with us in terms of evidence that supported your high confidence attribution that this was the North Koreans?
Ismael Valenzuela: Well, we typically talk -- when we talk about attribution, we typically talk about several things, you know, the indicators of compromise, the infrastructure that they use. Said before, we're tracking these threat actors for a long time and if you look at the publications that we have done in the past, you can see that this is not the first BlueNoroff publication that we have done. And the playbook, very, very distinct, and the motivation, right, the first motivation is, as I said before, financial to support the regime and to bypass the embargos, right, from the UN to this country. But we're not the only ones that we have seen this. There are other peers in the industry that have been reporting the same playbook coming out of BlueNoroff which always adds additional confidence to our assessment.
Dave Bittner: Hmm. So what are the takeaways here for defenders? What sort of things should security teams take away from your research?
Ismael Valenzuela: Well, the first one that you already talked about it's -- Dave, it's essentially training, right, proactive security training, security awareness. This is one of the oldest things in cybersecurity, knowing that, you know, you have to validate every single request, recognize the red flags of phishing, and routinely verifying meeting requests, especially when it is something that looks suspicious, right, via secondary contact method. Browser security, this is kind of a new field as well in cybersecurity, but maybe not so new for those that we have been around for a long time. But we see like very specific threats against browsers these days. There's a particular API, getUserMedia, that should only be available to like trusted domains, clipboard monitoring restrictions where feasible. Email and calendar security as well when inspecting these invites, especially when the invitations come from domains that look like domains we'd recognize, whether or not really those domains. And of course, threat intelligence, threat modeling, knowing exactly that if you are in the business of cryptocurrency, if you have wallets with high value, if you're a public figure, if you have a high position in an organization, know that these threat actors are going after you. And knowing this should drive the countermeasures. This is what I usually call "think red or blue," 15:30, right, think as an attacker to become a better defender.
Dave Bittner: You know, I think about an attack like this, and particularly the element with Calendly, I would fall for, because I feel like this is such a part of my day-to-day, right, of responding to calendar invites, sending out calendar invites, meeting with people in these online conference sessions like you and I are doing right now. It's such a part of my routine that I have to wonder would I stop to check, because I'm in such a habit of doing this every day.
Ismael Valenzuela: Well, it's funny you mentioned that, Dave, because I joined your podcast through this Calendly invite and [laughter] first thing I did when I clicked on it, it's like, "Hold, on a -- " before clicking on it, I want to say --
Dave Bittner: That's right. [laughs]
Ismael Valenzuela: -- "Hold on a second, is this actually Dave or not?"
Dave Bittner: Good for you. [laughs]
Ismael Valenzuela: But yeah, that's a reality, no one is free from any of this.
Dave Bittner: Yeah.
Ismael Valenzuela: But that's why you want to have like several controls along the way, because if something, you know, fails, it could be, you know, you under stress, checking -- you know, doing something urgently on your phone or -- at least you have other layers. And also having the information, right, listening to this podcast, having the right information to say, "Hold on a second, I'm going to, you know, verify and double-check, especially these types of requests." [ Music ]
Dave Bittner: Our thanks to Ismael Valenzuela from Arctic Wolf for joining us. The research is titled, "BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target the Web3 Sector." We'll have a link in the show notes. And that's "Research Saturday," brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly-changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com. This episode was produced by Liz Stokes, were mixed by Elliott Peltzman and Tre Hester. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I'm Dave Bittner. Thanks for listening. We'll see you back here next time. [ Music ]
