INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

North Korean Hackers Target Crypto Firms with ClickFix and AI-Led Lures

| 2026-04-28 08:00 CRITICAL HIGH
Executive Summary AI-generated
The recent incident attributed to BlueNoroff, a hacking team linked to the North Korea-linked Lazarus Group, has exposed vulnerabilities in global financial systems. The campaign, which began with high confidence, targeted over 20 countries and five regions, including the US, Singapore, and the UK. The attackers used stolen media from victims' compromised websites as part of their infrastructure, revealing a self-sustaining deepfake pipeline. Spear-phishing campaigns were also employed, utilizing social engineering techniques to impersonate prominent figures in the fintech industry. This sophisticated operation highlights the ongoing threat posed by Lazarus Group and its affiliates, who continue to exploit weaknesses in global systems for financial gain.
Technical Mitigations AI-generated
• Use secure and up-to-date software, such as a reputable antivirus program and a web browser with strong security features. • Implement robust password policies, including multi-factor authentication (MFA) whenever possible. • Regularly update operating systems, browsers, and other software to ensure you have the latest security patches.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Spanning OverCampaign Spanning Over Lazarus GroupLazarus GroupAPT38APT38
Target & Sectors
NORTH_AMERICA NORTH_AMERICA financefinance mediamedia
Incident Timeline
‎at least 2017
North Korean hackers used ClickFix to target crypto firms and AI-made Zoom lures in their SnatchCrypto operation.
target_region Bangladesh
organisation the 2016 Bangladesh Bank Swift
general_metric 2016 Bank Swift heist
financial $951 Stolen / Extorted Funds
financial $81 $ m.
‎January 23, 2026
Threat actors used spear phishing via typosquatted links and fake meeting invites to target cryptocurrency firms across over 20 countries.
tactic Phishing
tactic T1566 - Phishing
organisation Spear-
victims 100 additional targets
‎January 2026
North Korean hackers used ClickFix to target cryptocurrency firms and AI-made Zoom lures.
source_region Korea, Democratic People's Republic of
source_region DPRK
tactic Reconnaissance
organisation Picus Security
organisation Reconnaissance General Bureau
organisation RGB
‎March 2026
North Korean hackers used ClickFix and AI-Made Zoom Lures to target crypto firms.
threat_actor Lazarus Group
threat_actor APT38
organisation CageyChameleon
data_breach 950 files
organisation AES
‎April 27
Threat actors used ClickFix and AI-Made Zoom Lures to target crypto firms in the Korea, Democratic People's Republic of, DPRK.
source_region Korea, Democratic People's Republic of
source_region DPRK
organisation BlueNoroff
threat_actor Lazarus Group
‎2026/04/28
North Korean Hackers Target Crypto Firms with ClickFix and AI-Made Zoom Lures.
organisation North Korean Hackers
organisation ClickFix
organisation AI-Made Zoom Lures
threat_actor Lazarus Group
victims 100 additional targets
organisation Microsoft Teams
organisation Calendly
Tactical Metrics
Metrics
financial
951,000,000
Stolen / Extorted Funds
Metrics
financial
81
$ M.
Metrics
victims
100
Additional Targets
Metrics
data_breach
950
Files
Intelligence Sources
Infosecurity-Magazine 2026-04-28
Infosecurity-Magazine 2026-04-28