Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

The US Claims Pix Restricts Trade, Plus Chile’s Massive $88M Crypto Takedown

June 7, 2026

Crypto tax in Illinois FY2027 budget is one step away from becoming law

June 7, 2026

Filecoin: Why FIL’s breakdown below $0.80 signals a major shift

June 7, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms
North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms
Security and Privacy

North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms

February 11, 2026No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A North Korean hacking campaign is targeting financial technology and cryptocurrency firms with attacks which combine social engineering, deepfakes and MacOS malware.

The attacks have been detailed by Google Cloud’s Mandiant Threat Intelligence, which has attributed the campaign to UNC1069, a financially motivated threat group working out of North Korea. The end goal of the attacks is to steal cryptocurrency.

Researchers identified one campaign which began with a hijacked Telegram profile of a cryptocurrency executive. The individual had previously had their account compromised.

This account was used to send messages to others in the fintech sector to build up trust and rapport. The attacker then sent a calendar invite to join a meeting.

This meeting was designed to look like Zoom but was in fact hosted on infrastructure built by the attacker. According to Mandiant, one target said that after they joined the call, they were faced with a deepfake of the cryptocurrency executive.

While researchers have not been able to verify this, they noted AI-assisted social engineering scams are a known issue.

After joining the meeting, the attacker claimed that the victim was having audio issues and offered a solution to help.

However, this ruse was a ClickFix attack, a technique used by attackers, often accompanied by claims of a technical issue, to trick victims to running commands on their machine which will secretly provide the attackers with access and the ability to run code.

With the access, the attackers could drop malicious files onto the device, which they did in the form of Waveshaper and Hypercall, two backdoors which allowed attackers to gain further control.

See also  British Man Reveals $2,100,000 Loss From Downfall of Crypto Exchange FTX: Report

Then they installed information stealer malware and a data miner – Deepbreath and CHROMEPUSH – to gain further control and persistence over the machine.

This included the ability to steal credentials from the user’s Keychain, browser data from Chrome, Brave and Edge, user data from two different versions of Telegram and user data from Apple Notes.

Ultimately, all the login credentials and passwords an attacker might need to gain access to the victims’ accounts could be obtained, either to steal from them or use these accounts for additional social engineering.

“The volume of tooling deployed on a single host indicates a highly determined effort to harvest credentials, browser data and session tokens to facilitate financial theft,” said Mandiant.

“This incident was a targeted attack to harvest as much data as possible for a dual purpose; enabling cryptocurrency theft and fuelling future social engineering campaigns by leveraging victim’s identity and data,” the company added.

State-backed North Korean threat groups have a history of significant cryptocurrency heists and attacks which target organizations in financial technology.

In 2025 alone, North Korea made over $2bn from attacks targeting cryptocurrency and accounts for over 60% of all cryptocurrency stolen  during last year.

Source link

calls Crypto deepfake Firms Hackers Korean North Target Video
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

The US Claims Pix Restricts Trade, Plus Chile’s Massive $88M Crypto Takedown

June 7, 2026

Crypto tax in Illinois FY2027 budget is one step away from becoming law

June 7, 2026

Crypto News Today: AlphaPepe Presale Hits 9300 Holders While Bitcoin Price Prediction Targets $50,000

June 7, 2026

Hyperliquid Hit by UK FCA Warning as Crypto Perps Face Scrutiny

June 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Crypto markets hit $2.8T as liquidity improves – Can the recovery hold?

May 11, 2026

New York Department of Financial Services updates crypto listing rules with immediate effect

September 18, 2023

FutureBit Apollo II is More than Just a Bitcoin ASIC Miner for Home Users

November 28, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

The US Claims Pix Restricts Trade, Plus Chile’s Massive $88M Crypto Takedown

June 7, 2026

Crypto tax in Illinois FY2027 budget is one step away from becoming law

June 7, 2026

Filecoin: Why FIL’s breakdown below $0.80 signals a major shift

June 7, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$61,658.000.93%
  • ethereumEthereum(ETH)$1,599.461.62%
  • tetherTether(USDT)$1.000.02%
  • binancecoinBNB(BNB)$584.581.31%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.122.02%
  • solanaSolana(SOL)$64.132.10%
  • tronTRON(TRX)$0.3252721.42%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.46%
  • HyperliquidHyperliquid(HYPE)$59.530.31%