February 11 News, Google’s security team Mandiant disclosed that a North Korea-linked hacker group is using deepfake videos and fake Zoom calls to carry out highly targeted social engineering attacks against the cryptocurrency industry, and is deploying multiple malicious programs to steal assets and data.
The investigation shows that this operation was launched by the cyber threat group UNC1069. The group has been active since at least 2018 and shifted its focus from traditional finance to the Web3 space after 2023, targeting executives of crypto financial technology companies, software developers, and venture capital professionals. The incident began when an industry executive’s Telegram account was hijacked. The attacker impersonated the individual to contact targets, build trust, and then send fake Calendly video meeting invitations.
After victims clicked the link, they were directed to a fake Zoom domain controlled by the attacker. During the call, the attacker played a deepfake video of what appeared to be the CEO of another crypto company, and claimed there was an “audio malfunction,” tricking the target into running a supposed troubleshooting command on their computer. These commands triggered an infection chain on macOS and Windows systems, silently deploying up to seven malicious software programs.
Mandiant confirmed that these tools can steal Keychain credentials, browser cookies, login information, Telegram sessions, and local sensitive files. Researchers believe that the attackers aim both to directly acquire crypto assets and to gather intelligence for future scams. Deploying so many tools on a single device indicates a carefully planned targeted infiltration.
This incident is not isolated. By 2025, similar AI conference scams had caused losses exceeding $300 million; throughout the year, cyber operations related to North Korea stole approximately $2.02 billion in digital assets, a 51% increase. Chainalysis also pointed out that scam groups utilizing on-chain AI services are significantly more efficient than traditional methods.
As the barrier to deepfake technology continues to lower, the crypto industry faces unprecedented security challenges. Experts warn that online meetings involving funds and system permissions must strengthen multi-factor authentication and device isolation; otherwise, they could become the next attack vector.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Related Articles
sDOLA LlamaLend suffers flash loan price manipulation attack, losing approximately $240,000
ChainCatcher reports that sDOLA LlamaLend was subjected to a flash loan price manipulation attack, resulting in a loss of approximately $240,000. The attacker manipulated the sDOLA price, causing multiple accounts' health factors to drop below 0, triggering liquidation conditions and profiting from it.
GateNews51m ago
GoPlus: Beware of 26 malicious software packages released by North Korean hackers that can be remotely downloaded and execute Trojans
GoPlus Chinese Community issued a warning that North Korean hackers have published 26 malicious packages on the npm registry. These packages can execute hidden malicious code and steal user information. Users should verify the source of software packages and avoid using the listed malicious packages to prevent privacy leaks and asset loss.
GateNews3h ago
Former Los Angeles police officer convicted of kidnapping a teenager and stealing Bitcoin: $350,000 in digital assets stolen
Former Los Angeles Police Officer Eric Halem was convicted of kidnapping and robbing a teenage Bitcoin holder, valued at approximately $350,000. The case highlights the risks of cryptocurrency in crime, reminding investors to protect digital assets against theft and scams. Sentencing will take place on March 31.
GateNews3h ago
Korean Tax Authority leaks crypto wallet seed phrase, $5 million worth of digital assets instantly stolen
South Korean tax authorities accidentally leaked the mnemonic phrase of a tax evasion suspect's cryptocurrency wallet, resulting in digital assets worth approximately $5 million being stolen. Experts point out that there are vulnerabilities in the government's digital asset management, and the incident has raised concerns about the security of cryptocurrencies and the government's regulatory capabilities.
GateNews4h ago
OpenZeppelin audits EVMbench, finds data contamination
OpenZeppelin conducted an audit of EVMbench and found that the training data was contaminated, and at least four high-risk vulnerabilities are invalid forgeries. This affects the AI model's security assessment capabilities. If the AI has previously "seen" vulnerability reports, it will not accurately reflect its ability to discover new vulnerabilities. This highlights issues with the credibility of benchmark test data and methodologies.
MarketWhisper5h ago
SANAE TOKEN Collapse! Sanae Tanaka Denies Supporting Political Coins, Issuer Faces Backlash in Japan
Japanese Prime Minister Sanae Takaichi strongly denies involvement in the issuance of the cryptocurrency called SANAE TOKEN, which is promoted in her name and has caused social panic. The latest reports indicate that the coin's price has plummeted by over 50%. The issuer claims that the coin promotes political participation but was not authorized by the government, leading to public condemnation and legal issues. Investors should stay vigilant to avoid financial scams.
CryptoCity5h ago