Cryptocnews-Crypto News, Cryptocurrency News, Blockchain News, NFT News
    What's Hot

    Trader Who Nailed Epic Bitcoin 2018 Collapse Says BTC Must Surpass This Level – Or Else

    01/27/2026

    What the BPS ruling reveals about Australia’s crypto compliance gap

    01/27/2026

    Bitwise launches non-custodial DeFi vault as asset managers move on-chain

    01/27/2026
    Facebook Twitter Instagram
    • Business
    • Markets
    • Get In Touch
    • Our Authors
    Facebook Twitter Instagram
    Cryptocnews-Crypto News, Cryptocurrency News, Blockchain News, NFT News
    • Home
    • Business

      What the BPS ruling reveals about Australia’s crypto compliance gap

      01/27/2026

      Bitwise launches non-custodial DeFi vault as asset managers move on-chain

      01/27/2026

      Binance Co-Founder Declines Return After Trump Pardon

      01/26/2026

      BlackRock Files With SEC to Launch iShares Bitcoin Premium Income ETF

      01/26/2026

      Ether could retest the $2,749 support level: Check forecast

      01/26/2026
    • Technology
      1. Business
      2. Insights
      3. View All

      What the BPS ruling reveals about Australia’s crypto compliance gap

      01/27/2026

      Bitwise launches non-custodial DeFi vault as asset managers move on-chain

      01/27/2026

      Binance Co-Founder Declines Return After Trump Pardon

      01/26/2026

      BlackRock Files With SEC to Launch iShares Bitcoin Premium Income ETF

      01/26/2026

      What the BPS ruling reveals about Australia’s crypto compliance gap

      01/27/2026

      Bitwise launches non-custodial DeFi vault as asset managers move on-chain

      01/27/2026

      Strategy Extends Bitcoin Accumulation With New 2,932 BTC Buy

      01/27/2026

      Crypto Funds See Record Exodus: $1.7 Billion Leaves Market

      01/27/2026

      What the BPS ruling reveals about Australia’s crypto compliance gap

      01/27/2026

      Bitwise launches non-custodial DeFi vault as asset managers move on-chain

      01/27/2026

      EU Investigates X Over Alleged Failures to Curb Illegal Grok AI Content

      01/27/2026

      From marginal experiment to global market infrastructure: Tokenization is rewriting finance

      01/27/2026
    • Insights
      1. Bitcoin
      2. Ethereum
      3. Eurozone
      4. Monero
      5. View All

      What the BPS ruling reveals about Australia’s crypto compliance gap

      01/27/2026

      Bitwise launches non-custodial DeFi vault as asset managers move on-chain

      01/27/2026

      Stablecoin Liquidity Breaks Lower as $7B Exits Crypto in a Single Week

      01/26/2026

      Ether could retest the $2,749 support level: Check forecast

      01/26/2026

      What the BPS ruling reveals about Australia’s crypto compliance gap

      01/27/2026

      Bitwise launches non-custodial DeFi vault as asset managers move on-chain

      01/27/2026

      Bitcoin’s Coinbase Premium Stays Deeply Negative, Signaling Weak U.S. Spot Demand

      01/26/2026

      Ether could retest the $2,749 support level: Check forecast

      01/26/2026

      What the BPS ruling reveals about Australia’s crypto compliance gap

      01/27/2026

      Bitwise launches non-custodial DeFi vault as asset managers move on-chain

      01/27/2026

      Ether could retest the $2,749 support level: Check forecast

      01/26/2026

      AXS price pumps 12% as Axie Infinity outpaces gaming sector tokens

      01/26/2026

      What the BPS ruling reveals about Australia’s crypto compliance gap

      01/27/2026

      Bitwise launches non-custodial DeFi vault as asset managers move on-chain

      01/27/2026

      Ether could retest the $2,749 support level: Check forecast

      01/26/2026

      AXS price pumps 12% as Axie Infinity outpaces gaming sector tokens

      01/26/2026

      What the BPS ruling reveals about Australia’s crypto compliance gap

      01/27/2026

      Bitwise launches non-custodial DeFi vault as asset managers move on-chain

      01/27/2026

      Strategy Extends Bitcoin Accumulation With New 2,932 BTC Buy

      01/27/2026

      Crypto Funds See Record Exodus: $1.7 Billion Leaves Market

      01/27/2026
    • Markets
    • Get In Touch
    Cryptocnews-Crypto News, Cryptocurrency News, Blockchain News, NFT News
    Home»Technology»North Korea–Linked Hackers Use Deepfake Video Calls to Target Crypto Workers
    Technology

    North Korea–Linked Hackers Use Deepfake Video Calls to Target Crypto Workers

    adminBy admin01/27/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    In brief

    • Attackers have used a fake video call and a Zoom “audio fix” to deliver macOS malware.
    • The method matches a previously documented intrusion method tied to North Korea’s BlueNoroff, a Lazarus sub-group.
    • The incident comes as AI-driven impersonation scams pushed crypto losses to a record $17 billion in 2025.

    North Korea-linked hackers continue to use live video calls, including AI-generated deepfakes, to trick crypto developers and workers into installing malicious software on their own devices.

    In the latest instance disclosed by BTC Prague co-founder Martin Kuchař, attackers used a compromised Telegram account and a staged video call to push malware disguised as a Zoom audio fix, he said.

    The “high-level hacking campaign” appears to be “targeting Bitcoin and crypto users,” Kuchař disclosed Thursday on X.

    Attackers contact the victim and set up a Zoom or Teams call, Kuchař explained. During the call, they use an AI-generated video to appear as someone the victim knows.

    They then claim there is an audio problem and ask the victim to install a plugin or file to fix it. Once installed, the malware grants attackers full system access, allowing them to steal Bitcoin, take over Telegram accounts, and use those accounts to target others.

    It comes as AI-driven impersonation scams have pushed crypto-related losses to a record $17 billion in 2025, with attackers increasingly using deepfake video, voice cloning, and fake identities to deceive victims and gain access to funds, according to data from blockchain analytics firm Chainalysis.

    Similar attacks

    The attack, as described by Kuchař, closely matches a technique first documented by cybersecurity company Huntress, which reported in July last year that these attackers lure a target crypto worker into a staged Zoom call after initial contact on Telegram, often using a fake meeting link hosted on a spoofed Zoom domain.

    During the call, the attackers would claim there is an audio problem and instruct the victim to install what appears to be a Zoom-related fix, which is actually a malicious AppleScript that initiates a multi-stage macOS infection, according to Huntress.

    Once executed, the script disables shell history, checks for or installs Rosetta 2 (a translation layer) on Apple Silicon devices, and repeatedly prompts the user for their system password to gain elevated privileges.

    The study found that malware chain installs multiple payloads, including persistent backdoors, keylogging and clipboard tools, and crypto wallet stealers, a similar sequence Kuchař pointed to when he disclosed on Monday that his Telegram account was compromised and later used to target others in the same way.

    Social patterns

    Security researchers at Huntress have attributed the intrusion with high confidence to a North Korea-linked advanced persistent threat tracked as TA444, also known as BlueNoroff and by several other aliases operating under the umbrella term Lazarus Group, a state-sponsored group focused on cryptocurrency theft since at least 2017.

    When asked about the operational goals of these campaigns and whether they think there’s a correlation, Shān Zhang, chief information security officer at blockchain security firm Slowmist, told Decrypt that the latest attack on Kuchař is “possibly” connected to broader campaigns from the Lazarus Group.

    “No single indicator is decisive on its own; it’s the combination that matters,” Zhang said.”Deepfake-enabled lures typically rely on new or disposable meeting accounts and look-alike Zoom or Teams links, and the call quickly becomes highly scripted.”Attackers “create urgency and push the target” to install the so-called “Zoom/Teams fix” early in the conversation, he explained.

    “There is clear reuse across campaigns. We consistently see targeting of specific wallets and the use of very similar install scripts,” David Liberman, co-creator of decentralized AI compute network Gonka, told Decrypt.

    Images and video “can no longer be treated as reliable proof of authenticity,” Liberman said, adding that digital content “should be cryptographically signed by its creator, and such signatures should require multi-factor authorization.”

    Narratives, in contexts such as this, have become “an important signal to track and detect,” given how these attacks “rely on familiar social patterns,” he said.

    North Korea’s Lazarus Group is tied to campaigns against crypto firms, workers, and developers, using tailored malware and sophisticated social engineering to steal digital assets and access credentials.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    What the BPS ruling reveals about Australia’s crypto compliance gap

    01/27/2026

    Bitwise launches non-custodial DeFi vault as asset managers move on-chain

    01/27/2026

    EU Investigates X Over Alleged Failures to Curb Illegal Grok AI Content

    01/27/2026

    From marginal experiment to global market infrastructure: Tokenization is rewriting finance

    01/27/2026
    Add A Comment

    Leave A Reply Cancel Reply

    Top Posts

    Millennials Are Quitting Job to Become Day Traders

    01/20/2021

    Jack Dorsey Says Bitcoin Will Unite The World

    01/15/2021

    Hong Kong Customs Arrest Four in Crypto Laundering Bust

    01/15/2021

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo
    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    Trader Who Nailed Epic Bitcoin 2018 Collapse Says BTC Must Surpass This Level – Or Else

    01/27/2026

    What the BPS ruling reveals about Australia’s crypto compliance gap

    01/27/2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © {2025} Copyright CryptocNews.com
    • Home
    • Business
    • Markets
    • Technology
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.