North Korea Hacks Crypto Firms with AI Deepfakes
BitNewsBot -
  • UNC1069, a North Korean threat actor, is using sophisticated AI-generated deepfake videos and fake Zoom meetings to target the cryptocurrency sector.
  • The attack chain deploys up to seven unique malware families to steal credentials, browser data, and session tokens aimed at financial theft.
  • The group now focuses on Web3 targets like centralized exchanges and venture capital firms, shifting from traditional finance spear-phishing.

The North Korean cyber-espionage group UNC1069 has escalated its social engineering prowess, leveraging AI-generated deepfake videos in a complex campaign to steal from cryptocurrency firms, according to researchers. The intrusion begins with the threat actor impersonating venture capitalists on Telegram to lure victims into a phony Zoom meeting.

- Advertisement -

Victims are shown a convincing, fake video call interface displaying recorded or deepfake footage to simulate a live participant. Once trust is established, the page displays a bogus error message and prompts the user to run a troubleshooting command.

This “ClickFix” infection vector triggers the deployment of multiple new malware families. For macOS systems, an AppleScript drops a C++ information-gathering tool called WAVESHAPER.

Consequently, this executable distributes further payloads, including the Go-based downloader HYPERCALL. HYPERCALL then serves additional backdoors and stealers like HIDDENCALL and DEEPBREATH.

The Swift-based DEEPBREATH data miner specifically manipulates macOS security to access system credentials and data from browsers like Chrome and applications like Telegram. Meanwhile, the C++ malware CHROMEPUSH is deployed as a malicious browser extension to record keystrokes and extract cookies.

- Advertisement -

Mandiant analysts noted, “The volume of tooling deployed on a single host indicates a highly determined effort to harvest credentials, browser data, and session tokens to facilitate financial theft.” This campaign marks a significant expansion in the group’s capabilities as it intensifies its focus on the Web3 ecosystem.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:
Stay in the Loop

🔥 Join 1.2K Smart Traders

Get exclusive crypto insights, breaking news, and market analysis delivered straight to your inbox. No fluff, just facts.

Thank you!

You have successfully joined our subscriber list.

- Advertisement -



read more