New Deepfake Phishing Attack Targets Bitcoin Users via Zoom and Teams
ID: 402c50ae-68f0-5dfb-98ad-44952545b52c
STIX ID: report--402c50ae-68f0-5dfb-98ad-44952545b52c
Feed Name: GBHackers
A sophisticated, active phishing campaign targets Bitcoin users by sending Telegram links that initiate Zoom or Microsoft Teams calls; attackers employ AI-generated deepfake video to impersonate trusted contacts, then social-engineer victims into installing a malicious "plugin" that grants full remote access. The malware is used to steal bitcoin from hot wallets, hijack Telegram accounts to spread the campaign, and capture passwords and authentication tokens; the report includes practical mitigations such as avoiding calls from Telegram links, verifying identities out-of-band, and using reputable endpoint protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
