Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

U.S. CLARITY Act stablecoin bill faces May delay amid bank pushback

April 21, 2026

Were tariff refunds bought for 20 cents on the dollar by stablecoin-backed Treasurys custodian Cantor Fitzgerald?

April 21, 2026

Digital Empowerment for Traditional TCM – Laozhongyi and CUBE Platform Forge Strategic Partnership to Expand into Southeast Asia and the Middle East

April 21, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms
North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms
Security and Privacy

North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms

February 11, 2026No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A North Korean hacking campaign is targeting financial technology and cryptocurrency firms with attacks which combine social engineering, deepfakes and MacOS malware.

The attacks have been detailed by Google Cloud’s Mandiant Threat Intelligence, which has attributed the campaign to UNC1069, a financially motivated threat group working out of North Korea. The end goal of the attacks is to steal cryptocurrency.

Researchers identified one campaign which began with a hijacked Telegram profile of a cryptocurrency executive. The individual had previously had their account compromised.

This account was used to send messages to others in the fintech sector to build up trust and rapport. The attacker then sent a calendar invite to join a meeting.

This meeting was designed to look like Zoom but was in fact hosted on infrastructure built by the attacker. According to Mandiant, one target said that after they joined the call, they were faced with a deepfake of the cryptocurrency executive.

While researchers have not been able to verify this, they noted AI-assisted social engineering scams are a known issue.

After joining the meeting, the attacker claimed that the victim was having audio issues and offered a solution to help.

However, this ruse was a ClickFix attack, a technique used by attackers, often accompanied by claims of a technical issue, to trick victims to running commands on their machine which will secretly provide the attackers with access and the ability to run code.

With the access, the attackers could drop malicious files onto the device, which they did in the form of Waveshaper and Hypercall, two backdoors which allowed attackers to gain further control.

See also  Congresswoman Maxine Waters Questions Meta’s Ongoing Crypto Efforts

Then they installed information stealer malware and a data miner – Deepbreath and CHROMEPUSH – to gain further control and persistence over the machine.

This included the ability to steal credentials from the user’s Keychain, browser data from Chrome, Brave and Edge, user data from two different versions of Telegram and user data from Apple Notes.

Ultimately, all the login credentials and passwords an attacker might need to gain access to the victims’ accounts could be obtained, either to steal from them or use these accounts for additional social engineering.

“The volume of tooling deployed on a single host indicates a highly determined effort to harvest credentials, browser data and session tokens to facilitate financial theft,” said Mandiant.

“This incident was a targeted attack to harvest as much data as possible for a dual purpose; enabling cryptocurrency theft and fuelling future social engineering campaigns by leveraging victim’s identity and data,” the company added.

State-backed North Korean threat groups have a history of significant cryptocurrency heists and attacks which target organizations in financial technology.

In 2025 alone, North Korea made over $2bn from attacks targeting cryptocurrency and accounts for over 60% of all cryptocurrency stolen  during last year.

Source link

calls Crypto deepfake Firms Hackers Korean North Target Video
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

North Korean Blamed for $290m KelpDAO Crypto Heist

April 21, 2026

Chainalysis Flags Critical Blind Spot in DeFi Security as $292M Exploit Bypasses Burn Verification

April 21, 2026

Ripple’s Schwartz Flags DeFi Bridge Trade-Offs After KelpDAO Incident

April 20, 2026

North Korea’s crypto heist playbook is expanding and DeFi keeps getting hit

April 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Thanks to XRP, altcoins have started displacing Bitcoin

July 26, 2023

Did the SEC Just Declare War on NFTs?

August 30, 2023

Chainlink Announces Exciting Upgrades with Staking v0.2

October 23, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

U.S. CLARITY Act stablecoin bill faces May delay amid bank pushback

April 21, 2026

Were tariff refunds bought for 20 cents on the dollar by stablecoin-backed Treasurys custodian Cantor Fitzgerald?

April 21, 2026

Digital Empowerment for Traditional TCM – Laozhongyi and CUBE Platform Forge Strategic Partnership to Expand into Southeast Asia and the Middle East

April 21, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$75,906.000.77%
  • ethereumEthereum(ETH)$2,306.16-0.42%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.430.62%
  • binancecoinBNB(BNB)$631.961.01%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$85.480.19%
  • tronTRON(TRX)$0.3298200.51%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.35%
  • dogecoinDogecoin(DOGE)$0.0950230.09%