logo

Fake CEO, Real Hack: North Korea Uses AI Deepfakes to Steal Crypto

ID: 48080cd4-fc33-5dc0-be22-1c4e3907a61f

STIX ID: report--48080cd4-fc33-5dc0-be22-1c4e3907a61f

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-02-11

Date Updated: 2026-04-23

Author: Ddos

...
...

Mandiant describes UNC1069 using AI-generated deepfakes and sophisticated social-engineering to compromise a FinTech cryptocurrency target: attackers hijacked a Telegram contact, lured the victim into a spoofed Zoom/Calendly call with a deepfake CEO, then executed a "ClickFix" workflow to run malicious macOS scripts and deploy seven malware families (notably SILENCELIFT, DEEPBREATH, CHROMEPUSH) to steal credentials, browser cookies, and Notes data for financial theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.