North Korea Hacks Crypto Firms with AI Deepfakes

North Korean hackers use AI deepfakes and complex malware to steal cryptocurrency.

  • UNC1069, a North Korean threat actor, is using sophisticated AI-generated deepfake videos and fake Zoom meetings to target the cryptocurrency sector.
  • The attack chain deploys up to seven unique malware families to steal credentials, browser data, and session tokens aimed at financial theft.
  • The group now focuses on Web3 targets like centralized exchanges and venture capital firms, shifting from traditional finance spear-phishing.

The North Korean cyber-espionage group UNC1069 has escalated its social engineering prowess, leveraging AI-generated deepfake videos in a complex campaign to steal from cryptocurrency firms, according to researchers. The intrusion begins with the threat actor impersonating venture capitalists on Telegram to lure victims into a phony Zoom meeting.

- Advertisement -

Victims are shown a convincing, fake video call interface displaying recorded or deepfake footage to simulate a live participant. Once trust is established, the page displays a bogus error message and prompts the user to run a troubleshooting command.

This “ClickFix” infection vector triggers the deployment of multiple new malware families. For macOS systems, an AppleScript drops a C++ information-gathering tool called WAVESHAPER.

Consequently, this executable distributes further payloads, including the Go-based downloader HYPERCALL. HYPERCALL then serves additional backdoors and stealers like HIDDENCALL and DEEPBREATH.

The Swift-based DEEPBREATH data miner specifically manipulates macOS security to access system credentials and data from browsers like Chrome and applications like Telegram. Meanwhile, the C++ malware CHROMEPUSH is deployed as a malicious browser extension to record keystrokes and extract cookies.

- Advertisement -

Mandiant analysts noted, “The volume of tooling deployed on a single host indicates a highly determined effort to harvest credentials, browser data, and session tokens to facilitate financial theft.” This campaign marks a significant expansion in the group’s capabilities as it intensifies its focus on the Web3 ecosystem.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Core Scientific To Sell Remaining Bitcoin For AI Pivot

Core Scientific plans to "monetize substantially all" of its Bitcoin holdings in 2025, with...

MARA’s Bitcoin lending brings $32.1M income as policy shifts

MARA Holdings revised its treasury strategy to allow for Bitcoin sales from its $4.7...

Hedera February 2026 Developer Highlights Released

Hedera announced the ongoing migration from the AccountBalanceQuery and a key integration with Axelar...

Milei’s Secret Blockchain Pact with LIBRA Creator Exposed

A confidential blockchain advisory agreement between Libra co-creator Hayden Davis and Argentine President Javier...

US Bitcoin Miner MARA Considers Selling Holdings

MARA Holdings may sell Bitcoin from its balance sheet depending on market conditions, according...

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!