logo

North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam

ID: 226f0d99-dd4e-5580-a10e-3f16c89411cc

STIX ID: report--226f0d99-dd4e-5580-a10e-3f16c89411cc

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2026-02-10

Date Updated: 2026-05-01

...
...

Mandiant exposed a tailored UNC1069 campaign where North Korean operators used Telegram-based social engineering and a fake Zoom/Calendly meeting (including an alleged deepfake) plus a ClickFix troubleshooting ruse to infect a macOS host. The attackers deployed multiple bespoke tools—backdoors WAVESHAPER and HYPERCALL and data miners DEEPBREATH and CHROMEPUSH—to steal credentials, browser data, Telegram content and other sensitive files, likely to support cryptocurrency theft and future impersonation campaigns; the group continues to target financial and crypto-sector entities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.