ZoomClutch is a Swift-based macOS credential-harvesting implant used by the North Korea-linked BlueNoroff threat actor, also tracked as Sapphire Sleet, APT38, Stardust Chollima, TA444, and Alluring Pisces, as part of the SnatchCrypto operation. It is associated with the GhostCall campaign and is delivered through fake Zoom-themed meeting lures, with a related Microsoft Teams-themed variant tracked as TeamsClutch. The malware masquerades as a legitimate Zoom application, prompts the victim to enter their macOS system password, validates the password locally using Apple Open Directory, and exfiltrates the captured credentials to an external server. Reporting states that DownTroy can deploy ZoomClutch or TeamsClutch in multi-stage macOS infection chains initiated from Telegram-delivered social engineering and phishing pages impersonating Zoom or Teams. Observed targeting focused on executives, managers, developers, and other personnel in the Web3 and blockchain ecosystem, including tech companies and venture capital firms, with victims reported across multiple countries, especially in APAC. High-confidence behavior directly described in the source content is limited to its disguise as Zoom, Swift implementation, password prompting/validation, and credential exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ZoomClutch/TeamsClutch: the fake Zoom/Teams application ... The implant is written in Swift and functions as a macOS credentials harvester, disguised as the Zoom videoconferencing application.
ZoomClutch or TeamsClutch, which uses a Swift-based implant that masquerades as Zoom or Teams while harboring functionality to prompt the user to enter their system password ... and exfiltrate the details to an external server
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon accessing the fake site, the target is presented with a page carefully designed to mirror the appearance of Zoom in a browser... Approximately three to five seconds later, an error message appears... prompting them to download a Zoom SDK update file through a link labeled 'Update Now'.
Once contact is established with the target, they use Calendly to schedule a meeting and then share a meeting link through domains that mimic Zoom... In September 2025, we discovered that the group is shifting from cloning the Zoom UI in their attacks to Microsoft Teams.
The actor reaches out to targets on Telegram by impersonating venture capitalists and, in some cases, using compromised accounts of real entrepreneurs and startup founders... In the GhostHire campaign, BlueNoroff approaches Web3 developers and tricks them into downloading and executing a GitHub repository containing malware under the guise of a skill assessment during a recruitment process.
"...prompt the user to enter their system password in order to complete the app update and exfiltrate the details..."
The downloader script includes a harvesting function that searches for files associated with password management applications... ZoomClutch steals macOS passwords by displaying a fake Zoom dialog... ubd.sh is the browser credentials and macOS Keychains stealer module.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A payload delivered in the GhostCall chain; presented as related to Zoom-themed lures and deployed via DownTroy.
Swift-based macOS implant masquerading as Zoom that prompts the user for their system password during a fake update flow and exfiltrates the entered credentials to an external server.
A macOS credential-harvesting implant disguised as Zoom or Microsoft Teams. It presents fake password prompts, validates entered passwords locally via Open Directory, logs them, and exfiltrates verified credentials to C2. It appears to support subsequent malware deployment in BlueNoroff intrusion chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.