Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

June 25, 2026

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

June 25, 2026
Facebook X (Twitter) Instagram
Thursday, June 25
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms
News

North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms

Team-CWDBy Team-CWDFebruary 11, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A North Korean hacking campaign is targeting financial technology and cryptocurrency firms with attacks which combine social engineering, deepfakes and MacOS malware.

The attacks have been detailed by Google Cloud’s Mandiant Threat Intelligence, which has attributed the campaign to UNC1069, a financially motivated threat group working out of North Korea. The end goal of the attacks is to steal cryptocurrency.

Researchers identified one campaign which began with a hijacked Telegram profile of a cryptocurrency executive. The individual had previously had their account compromised.

This account was used to send messages to others in the fintech sector to build up trust and rapport. The attacker then sent a calendar invite to join a meeting.

This meeting was designed to look like Zoom but was in fact hosted on infrastructure built by the attacker. According to Mandiant, one target said that after they joined the call, they were faced with a deepfake of the cryptocurrency executive.

While researchers have not been able to verify this, they noted AI-assisted social engineering scams are a known issue.

After joining the meeting, the attacker claimed that the victim was having audio issues and offered a solution to help.

However, this ruse was a ClickFix attack, a technique used by attackers, often accompanied by claims of a technical issue, to trick victims to running commands on their machine which will secretly provide the attackers with access and the ability to run code.

With the access, the attackers could drop malicious files onto the device, which they did in the form of Waveshaper and Hypercall, two backdoors which allowed attackers to gain further control.

Then they installed information stealer malware and a data miner – Deepbreath and CHROMEPUSH – to gain further control and persistence over the machine.

This included the ability to steal credentials from the user’s Keychain, browser data from Chrome, Brave and Edge, user data from two different versions of Telegram and user data from Apple Notes.

Ultimately, all the login credentials and passwords an attacker might need to gain access to the victims’ accounts could be obtained, either to steal from them or use these accounts for additional social engineering.

“The volume of tooling deployed on a single host indicates a highly determined effort to harvest credentials, browser data and session tokens to facilitate financial theft,” said Mandiant.

“This incident was a targeted attack to harvest as much data as possible for a dual purpose; enabling cryptocurrency theft and fuelling future social engineering campaigns by leveraging victim’s identity and data,” the company added.

State-backed North Korean threat groups have a history of significant cryptocurrency heists and attacks which target organizations in financial technology.

In 2025 alone, North Korea made over $2bn from attacks targeting cryptocurrency and accounts for over 60% of all cryptocurrency stolen  during last year.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog
Next Article Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions
Team-CWD
  • Website

Related Posts

News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
News

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

June 25, 2026
News

Twenty Million US IP Connections Used by Proxy Services

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How to help older family members avoid scams

October 31, 2025

What it is and how to protect yourself

January 8, 2026

What is it, and how do I get it off my device?

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.