North Korean hackers use AI deepfake Zoom to scam, cryptocurrency companies face dual attack of targeted "social engineering + Trojan"

February 11 News, Google’s security team Mandiant disclosed that a North Korea-linked hacker group is using deepfake videos and fake Zoom calls to carry out highly targeted social engineering attacks against the cryptocurrency industry, and is deploying multiple malicious programs to steal assets and data.

The investigation shows that this operation was launched by the cyber threat group UNC1069. The group has been active since at least 2018 and shifted its focus from traditional finance to the Web3 space after 2023, targeting executives of crypto financial technology companies, software developers, and venture capital professionals. The incident began when an industry executive’s Telegram account was hijacked. The attacker impersonated the individual to contact targets, build trust, and then send fake Calendly video meeting invitations.

After victims clicked the link, they were directed to a fake Zoom domain controlled by the attacker. During the call, the attacker played a deepfake video of what appeared to be the CEO of another crypto company, and claimed there was an “audio malfunction,” tricking the target into running a supposed troubleshooting command on their computer. These commands triggered an infection chain on macOS and Windows systems, silently deploying up to seven malicious software programs.

Mandiant confirmed that these tools can steal Keychain credentials, browser cookies, login information, Telegram sessions, and local sensitive files. Researchers believe that the attackers aim both to directly acquire crypto assets and to gather intelligence for future scams. Deploying so many tools on a single device indicates a carefully planned targeted infiltration.

This incident is not isolated. By 2025, similar AI conference scams had caused losses exceeding $300 million; throughout the year, cyber operations related to North Korea stole approximately $2.02 billion in digital assets, a 51% increase. Chainalysis also pointed out that scam groups utilizing on-chain AI services are significantly more efficient than traditional methods.

As the barrier to deepfake technology continues to lower, the crypto industry faces unprecedented security challenges. Experts warn that online meetings involving funds and system permissions must strengthen multi-factor authentication and device isolation; otherwise, they could become the next attack vector.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

To publish a crypto post for the first time, you must verify! X rolls out new anti-scam rules to prevent hackers from stealing accounts and promoting spam coins

Community platform X has rolled out a mandatory verification mechanism for cryptocurrency-related content to address increasingly severe scam problems. The mechanism will lock accounts the first time they mention cryptocurrency, requiring users to complete identity verification. According to data, in 2025, crypto scams are expected to reach $17 billion, and social media platforms have become an important source of scams. The new measures are intended to reduce the success rate of scams that use highly trusted accounts, but scam activity is still expanding rapidly, and prevention efforts face challenges.

CryptoCity4h ago

Americans’ losses to crypto scams rose to over $11 billion last year, FBI reports

In 2025, Americans faced $11.4 billion in losses from cryptocurrency scams, marking a 22% increase from 2024. Organized criminal enterprises, primarily from Southeast Asia, exploit victims to operate these scams. The overall rise in cybercrime shows a growing threat.

CoinDesk9h ago

Posting your first crypto post to verify! X rolls out new anti-fraud rules to prevent hackers from stealing accounts—cracking down on scam-coin spam promotion

The social media platform X is rolling out a mandatory verification mechanism for cryptocurrency-related content to address increasingly severe scam problems. The mechanism will lock an account when it is first mentioned in relation to cryptocurrency, requiring users to complete identity verification. According to data, in 2025, crypto scams are expected to reach $17.0 billion, and social media platforms have become an important source of scams. The new measure is intended to reduce the success rate of scams that rely on high-trust accounts used by hackers; however, scam activity is still expanding rapidly, and preventive measures face challenges.

CryptoCity10h ago

Nobel Prize in Physics laureate warns: quantum computing could crack Bitcoin private keys within minutes

Former Google quantum hardware head John Martinis warns that Bitcoin could become a target for quantum computing attacks. Quantum computers could derive Bitcoin private keys within minutes, posing a greater threat than traditional financial systems. He recommends that the community plan quantum-resistance upgrades as early as possible to address threats over the next 5 to 10 years.

GateNews11h ago

The Ministry of State Security warns: Token scams are occurring frequently; you may be involved in illegal financial activities or be exploited by overseas intelligence agencies

The Ministry of State Security has recently warned about various scams that use the slogan “accumulating Tokens can make you rich” and said these activities endanger the country’s economic security. It also urged the public to handle illegal cryptocurrency trading with caution.

GateNews12h ago
Comment
0/400
00001clvip
· 02-11 10:37
Purely a mafia!
View OriginalReply0