North Korean hackers use AI deepfake Zoom to scam, cryptocurrency companies face dual attack of targeted "social engineering + Trojan"

February 11 News, Google’s security team Mandiant disclosed that a North Korea-linked hacker group is using deepfake videos and fake Zoom calls to carry out highly targeted social engineering attacks against the cryptocurrency industry, and is deploying multiple malicious programs to steal assets and data.

The investigation shows that this operation was launched by the cyber threat group UNC1069. The group has been active since at least 2018 and shifted its focus from traditional finance to the Web3 space after 2023, targeting executives of crypto financial technology companies, software developers, and venture capital professionals. The incident began when an industry executive’s Telegram account was hijacked. The attacker impersonated the individual to contact targets, build trust, and then send fake Calendly video meeting invitations.

After victims clicked the link, they were directed to a fake Zoom domain controlled by the attacker. During the call, the attacker played a deepfake video of what appeared to be the CEO of another crypto company, and claimed there was an “audio malfunction,” tricking the target into running a supposed troubleshooting command on their computer. These commands triggered an infection chain on macOS and Windows systems, silently deploying up to seven malicious software programs.

Mandiant confirmed that these tools can steal Keychain credentials, browser cookies, login information, Telegram sessions, and local sensitive files. Researchers believe that the attackers aim both to directly acquire crypto assets and to gather intelligence for future scams. Deploying so many tools on a single device indicates a carefully planned targeted infiltration.

This incident is not isolated. By 2025, similar AI conference scams had caused losses exceeding $300 million; throughout the year, cyber operations related to North Korea stole approximately $2.02 billion in digital assets, a 51% increase. Chainalysis also pointed out that scam groups utilizing on-chain AI services are significantly more efficient than traditional methods.

As the barrier to deepfake technology continues to lower, the crypto industry faces unprecedented security challenges. Experts warn that online meetings involving funds and system permissions must strengthen multi-factor authentication and device isolation; otherwise, they could become the next attack vector.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

OpenAI Releases an Announcement on a Third-Party Library Security Incident: No Evidence of User Data Leaks or System Intrusion Found

OpenAI issued a security advisory on April 11 confirming that it identified a security issue involving the third-party library Axios, but found no evidence that user data was accessed. To ensure security, the company requires all macOS users to update to the latest version to prevent the risk of forged applications.

GateNews7m ago

Blockchain security losses from 2026 to date are nearly $800 million, with incidents related to North Korea accounting for about 42%.

Since January 1, 2026, CertiK Alert has recorded 163 blockchain security incidents, with total losses of about $796.7 million. Of these, 12 were related to North Korean hacker organizations, with losses of about $329 million, accounting for 42% of total losses. Compared with the 60% share in 2025, it has declined.

GateNews2h ago

Drift hacked for $280 million—legal action! A U.S. law firm files a class-action lawsuit against Circle, alleging it allowed hackers to launder money without freezing funds

A U.S. law firm Gibbs Mura is launching an investigation into a class-action lawsuit regarding the April 1 Drift Protocol hack, alleging that stablecoin issuer USDC’s issuer Circle failed to freeze $230 million of the stolen funds. The firm will investigate Circle’s alleged double standards in the incident and its monitoring vulnerabilities. This case is expected to have a major impact on the legal liability of stablecoin issuers.

動區BlockTempo10h ago

Phantom Wallet Crashes Big Time! During the Airdrop Period, Token Prices Get Thrown Off, Balances Go to Zero—Users Blast the “Losses”

Phantom, a wallet in the Solana ecosystem, experienced a service outage during the airdrop, causing abnormal token price and account balance displays and affecting users’ transactions. Some users therefore incurred losses and are demanding compensation. Security experts warn of the risk of phishing attacks and advise users to verify on-chain data. Although the issue has been fixed, the trust crisis still needs to be monitored. This incident highlights the challenges self-custody wallets face in terms of system stability and user experience.

区块客12h ago

Circle Responds to the Drift Protocol Hack: USDC Freezing Must Be Executed Legally, Urges Faster Crypto Legislation

Circle’s Chief Strategy Officer Dante Disparte responded to the Drift Protocol theft incident, emphasizing that freezing USDC is being carried out according to law, calling for stronger coordination between law and technology, and suggesting that DeFi protocols should draw on protection mechanisms from traditional markets to advance legal protection of property rights and financial privacy.

GateNews13h ago
Comment
0/400
00001clvip
· 02-11 10:37
Purely a mafia!
View OriginalReply0