North Korea Hacks Crypto Firms with AI Deepfakes

North Korean hackers use AI deepfakes and complex malware to steal cryptocurrency.

  • UNC1069, a North Korean threat actor, is using sophisticated AI-generated deepfake videos and fake Zoom meetings to target the cryptocurrency sector.
  • The attack chain deploys up to seven unique malware families to steal credentials, browser data, and session tokens aimed at financial theft.
  • The group now focuses on Web3 targets like centralized exchanges and venture capital firms, shifting from traditional finance spear-phishing.

The North Korean cyber-espionage group UNC1069 has escalated its social engineering prowess, leveraging AI-generated deepfake videos in a complex campaign to steal from cryptocurrency firms, according to researchers. The intrusion begins with the threat actor impersonating venture capitalists on Telegram to lure victims into a phony Zoom meeting.

- Advertisement -

Victims are shown a convincing, fake video call interface displaying recorded or deepfake footage to simulate a live participant. Once trust is established, the page displays a bogus error message and prompts the user to run a troubleshooting command.

This “ClickFix” infection vector triggers the deployment of multiple new malware families. For macOS systems, an AppleScript drops a C++ information-gathering tool called WAVESHAPER.

Consequently, this executable distributes further payloads, including the Go-based downloader HYPERCALL. HYPERCALL then serves additional backdoors and stealers like HIDDENCALL and DEEPBREATH.

The Swift-based DEEPBREATH data miner specifically manipulates macOS security to access system credentials and data from browsers like Chrome and applications like Telegram. Meanwhile, the C++ malware CHROMEPUSH is deployed as a malicious browser extension to record keystrokes and extract cookies.

- Advertisement -

Mandiant analysts noted, “The volume of tooling deployed on a single host indicates a highly determined effort to harvest credentials, browser data, and session tokens to facilitate financial theft.” This campaign marks a significant expansion in the group’s capabilities as it intensifies its focus on the Web3 ecosystem.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

China’s Treasury Pullback Sparks Crypto Fear Amid Fed, Japan

Crypto analyst Paul Barron warns China's pullback from U.S. Treasuries may spark a global...

Arkham Exchange: Altman-Backed Crypto Platform Shuts Down

Arkham Intelligence, the blockchain analytics firm, is reportedly shutting down its cryptocurrency exchange, Arkham...

Yuan Soars to 15-Month High Amid Shift from US Treasuries

The Chinese yuan reached its strongest level against the US dollar since May 2023,...

Crypto Markets Cool Amid CLARITY Act Stalem

Cryptocurrency markets declined on Tuesday with over $213 million in total liquidations, primarily from...

Bithumb Seeks Return of $43B Bitcoin Sent by Mistake

Bithumb is contacting users who withdrew or sold billions in mistakenly-credited Bitcoin to negotiate...

Must Read

Tutorial: How to Buy a Domain Name Permanently? (Super Easy)

Are you ready to establish a permanent online presence and you want to buy a domain forever?In this tutorial, we'll show you how to...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!