The post North Korea state hackers turn to deepfake Zoom calls to hack crypto firms appeared on BitcoinEthereumNews.com. North Korean state hackers are targetingThe post North Korea state hackers turn to deepfake Zoom calls to hack crypto firms appeared on BitcoinEthereumNews.com. North Korean state hackers are targeting

North Korea state hackers turn to deepfake Zoom calls to hack crypto firms

North Korean state hackers are targeting crypto firms with several unique pieces of malware deployed alongside multiple scams, including fake Zoom meetings. 

The North Korea-linked threat actor known as UNC1069 has been observed targeting the crypto sector to steal sensitive data from Windows and macOS systems with the ultimate goal of facilitating financial theft.

UNC1069 was assessed to be active from April 2018. It has a history of running social engineering campaigns for financial gain using fake meeting invites and posing as investors from reputable companies. 

Fake Zoom call deploys malware attack on crypto firm

In its latest report, Google Mandiant researchers detailed their investigation into an intrusion targeting a FinTech company in the crypto industry. According to investigators, the intrusion began with a compromised Telegram account belonging to a crypto industry executive. 

The attackers used the hijacked profile to contact the victim. They gradually built trust before sending a Calendly invitation for a video meeting. The meeting link directed the target to a fake Zoom domain hosted on infrastructure under the threat actors’ control.

During the call, the victim reported seeing what appeared to be a deepfake video of a CEO from another crypto company.

“While Mandiant was unable to recover forensic evidence to independently verify the use of AI models in this specific instance, the reported ruse is similar to a previously publicly reported incident with similar characteristics, where deepfakes were also allegedly used,” the report stated.

Attack chain. Source: Google Cloud

The attackers created the impression of audio problems in the meeting to justify the next step. They instructed the victim to run troubleshooting commands on their device. Those commands, tailored for both macOS and Windows systems, secretly initiated the infection chain. As a result, several malware components were activated.

Mandiant identified seven distinct types of malware used during the attack. The tools were designed to access keychain and steal passwords, retrieve browser cookies and login information, access Telegram session information, and obtain other private files.

Investigators assessed that the objective was twofold: To enable potential crypto theft and harvest data that could support future social engineering attacks. The investigation revealed an unusually large volume of tooling dropped onto a single host. 

AI-linked scam clusters show higher operational efficiency

The incident is part of a broader pattern. North Korean-linked actors siphoned more than $300 million by posing as trusted industry figures during fraudulent Zoom and Microsoft Teams meetings.

The scale of activity throughout the year was even more striking. As reported by Cryptopolitan, North Korean threat groups were responsible for $2.02 billion in stolen digital assets in 2025, a 51% increase from the previous year.

Chainalysis also revealed that scam clusters tied to AI service providers show higher operational efficiency than those without such links. According to the firm, this trend suggests a future in which AI becomes a standard component of most scam operations.

In a report published last November, the Google Threat Intelligence Group (GTIG) noted the threat actor’s use of generative artificial intelligence (AI) tools, such as Gemini. They use them to produce lure materials and other crypto-related messaging as part of their efforts to support their social engineering campaigns.

The group has also been observed attempting to misuse Gemini to develop code to steal crypto assets. They also leverage deepfake images and video lures mimicking individuals in the crypto industry in their campaigns to distribute a backdoor called BIGMACHO to victims by passing it off as a Zoom software development kit (SDK).

Source: https://www.cryptopolitan.com/north-korea-hackers-deepfake-hack-firms/

Market Opportunity
Cloud Logo
Cloud Price(CLOUD)
$0.04093
$0.04093$0.04093
-0.02%
USD
Cloud (CLOUD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40
Adam Wainwright Takes The Mound Again Honor Darryl Kile

Adam Wainwright Takes The Mound Again Honor Darryl Kile

The post Adam Wainwright Takes The Mound Again Honor Darryl Kile appeared on BitcoinEthereumNews.com. Adam Wainwright of the St. Louis Cardinals in the dugout during the second inning against the Miami Marlins at Busch Stadium on July 18, 2023 in St. Louis, Missouri. (Photo by Brandon Sloter/Image Of Sport/Getty Images) Getty Images St. Louis Cardinals lifer Adam Wainwright is a pretty easygoing guy, and not unlikely to talk with you about baseball traditions and barbecue, or even share a joke. That personality came out last week during our Zoom call when I mentioned for the first time that I’m a Chicago Cubs fan. He responded to the mention of my fandom, “So far, I don’t think this interview is going very well.” Yet, Wainwright will return to Busch Stadium on September 19 on a more serious note, this time to honor another former Cardinal and friend, the late Darryl Kile. Wainwright will take the mound not as a starting pitcher, but to throw out the game’s ceremonial first pitch. Joining him on the mound will be Kile’s daughter, Sierra, as the two help launch a new program called Playing with Heart. “Darryl’s passing was a reminder that heart disease doesn’t discriminate, even against elite athletes in peak physical shape,” Wainwright said. “This program is about helping people recognize the risks, take action, and hopefully save lives.” Wainwright, who played for the St. Louis Cardinals as a starting pitcher from 2005 to 2023, aims to merge the essence of baseball tradition with a crucial message about heart health. Kile, a beloved pitcher for the Cardinals, tragically passed away in 2002 at the age of 33 as a result of early-onset heart disease. His sudden death shook the baseball world and left a lasting impact on teammates, fans, and especially his family. Now, more than two decades later, Sierra Kile is stepping forward with Wainwright to…
Share
BitcoinEthereumNews2025/09/18 02:08
US nonfarm payrolls double forecast with 130K jobs added

US nonfarm payrolls double forecast with 130K jobs added

The post US nonfarm payrolls double forecast with 130K jobs added appeared on BitcoinEthereumNews.com. US employers added 130,000 jobs in January, nearly doubling
Share
BitcoinEthereumNews2026/02/11 22:04