TeamsClutch is a Swift-based implant associated with the North Korea-linked Lazarus Group sub-cluster BlueNoroff (also tracked as APT38, Sapphire Sleet, CryptoCore, and CageyChameleon). It has been reported in Kaspersky’s coverage of the GhostCall and broader SnatchCrypto activity targeting the Web3 and blockchain ecosystem, as well as executives at technology companies and venture capital firms. TeamsClutch is deployed in GhostCall infection chains on macOS after Telegram-based social engineering lures direct victims to fake Zoom or Microsoft Teams meeting pages that prompt a malicious SDK update download. The malware masquerades as Microsoft Teams, prompts the user to enter their system password, and exfiltrates that password to an external server. The content states that the actor recently shifted lures from Zoom to Microsoft Teams, and that DownTroy can install fake applications disguised as Zoom or Teams and deploy TeamsClutch or ZoomClutch as follow-on payloads. High-confidence related context includes targeting of macOS users in multiple countries including Japan, Italy, France, Singapore, Turkey, Spain, Sweden, India, and Hong Kong.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ZoomClutch or TeamsClutch, which uses a Swift-based implant that masquerades as Zoom or Teams while harboring functionality to prompt the user to enter their system password ... and exfiltrate the details to an external server
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon accessing the fake site, the target is presented with a page carefully designed to mirror the appearance of Zoom in a browser... Approximately three to five seconds later, an error message appears... prompting them to download a Zoom SDK update file through a link labeled 'Update Now'.
Once contact is established with the target, they use Calendly to schedule a meeting and then share a meeting link through domains that mimic Zoom... In September 2025, we discovered that the group is shifting from cloning the Zoom UI in their attacks to Microsoft Teams.
The actor reaches out to targets on Telegram by impersonating venture capitalists and, in some cases, using compromised accounts of real entrepreneurs and startup founders... In the GhostHire campaign, BlueNoroff approaches Web3 developers and tricks them into downloading and executing a GitHub repository containing malware under the guise of a skill assessment during a recruitment process.
"...prompt the user to enter their system password in order to complete the app update and exfiltrate the details..."
The downloader script includes a harvesting function that searches for files associated with password management applications... ZoomClutch steals macOS passwords by displaying a fake Zoom dialog... ubd.sh is the browser credentials and macOS Keychains stealer module.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A payload delivered in the GhostCall chain; likely aligned to meeting-app lures and deployed via DownTroy.
Swift-based macOS implant masquerading as Microsoft Teams that prompts the user for their system password during a fake update flow and exfiltrates the entered credentials to an external server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.