A fake Zoom update empties your iCloud Keychain
A trusted Telegram contact invites you to a video call, a fake Zoom update pops up mid-call, and your iCloud Keychain gets emptied.
What’s really happening mid-call
BlueNoroff, the North Korean banner that targets crypto professionals, exploits no flaw. Zero exploit, zero CVE. Just social engineering, scaled into an industrial chain. The research comes from JUMPSEC, the “ClickFake Interview” cluster is tracked by Sekoia, and The Hacker News picked it up on July 24, 2026.
Here’s how it goes. A contact you’ve met in person messages you on Telegram, except their account has been hijacked. They send you a Calendly link in their name, which redirects you to a typosquatted Zoom or Teams domain, us.zoom.06webin.us. You type your name, you allow the camera, and the kit gets to work behind your back. It captures your video stream via mediasoup WebRTC and profiles the crypto wallet extensions installed in your browser. Then a fake message, “your mic isn’t working”, followed by a “Zoom SDK Update” prompt. You click to fix your mic, you install the payload.
On macOS, the rest unfolds without you. A shell script downloads a fake Teams or Zoom installer, a stealer extracts Chrome’s master keys from your macOS login keychain, where Chrome stores its encryption key, the ones that unlock your crypto wallet extensions, and exfiltrates everything through a Telegram channel named “Aurora”, before dropping further payloads. On the Windows side, the variant disables Defender via a PowerShell loader and hunts for Telegram sessions in Chrome, Edge, Brave and Firefox. Same actor, two chains.
Two details change the scale. The video calls are faked with deepfakes, AI-generated faces layered over real body language, captured from earlier victims. And the mechanism self-propagates, each compromised Telegram account becomes the trusted sender for the next one. Five versions of the kit have been spotted between May 31 and July 14, 2026, the operator is tied to the Telegram bot @alchemy_john_mac. This is no one-off, it’s a factory that iterates.
The technique has a name, ClickFix, and it already drags a trail of victims behind it.
Read next: ClickFix, the fake fix that makes you launch the malware yourself
The third ClickFix on macOS in six weeks
Do the math. CrashStealer in July, ClickLock before it, now BlueNoroff. Three times in six weeks the same pattern has hit macOS, one harmless gesture that triggers the install. The vector is going industrial, and this version aims straight at your keychain, where macOS stores your browser’s keys.
What protects you here is neither antivirus nor notarization. It’s a behavioral rule, simple and absolute, never install a binary offered to you during a meeting. Zoom doesn’t ship you an “SDK Update” mid-call. Neither does Teams. An update that surfaces during a video call is not an update, it’s the payload.
There’s a stack angle, provided you’re honest about its reach. Proton Meet is end-to-end encrypted and runs in your browser, with no native client to install. So the “install this SDK update” pretext has nowhere to latch on, there’s no app to update. It shrinks the attack surface, it doesn’t replace the behavioral rule. Switching to Proton Meet does not protect you from this phishing, social engineering depends on no tool.
Read next: Proton Meet, the encrypted video call that runs in your browser
The part that should worry you is the sender. It’s not a stranger, it’s someone whose hand you’ve shaken. Interpersonal trust is the vector, not your gullibility. A genuine Telegram account, a name you recognize, a meeting link, that’s all it takes.
What you do now
1. An install prompt that appears during a meeting, you refuse, no exceptions. Zoom, Teams, no video call asks you to install an “SDK Update” or to fix your mic through a download. You leave the call, you click nothing.
2. A meeting link, even sent by a real contact, you verify it through another channel before clicking. A voice call, a Signal message, “did you really send me this Calendly?”. The Telegram account on the other end may already be hijacked.
3. Look at the URL before allowing your camera. us.zoom.06webin.us is not a Zoom domain, it’s typosquatting. The real Zoom is zoom.us. A long trailing subdomain grafted onto an unknown name, you close the tab.
4. Install an outbound firewall and let it speak. Little Snitch or LuLu see the exfiltration leave for Telegram, exactly when the stealer empties your keychain. It’s your last line when everything else has been bypassed.
Read next: Little Snitch vs LuLu, which outbound firewall for your Mac
Sources
- The Hacker News, which relayed the research on July 24, 2026
- Primary research JUMPSEC, analysis of the BlueNoroff phishing kit
- “ClickFake Interview” cluster tracked by Sekoia