logo

North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms

ID: 840405b6-5c2f-5db5-b987-6321f275bf1b

STIX ID: report--840405b6-5c2f-5db5-b987-6321f275bf1b

Feed Name: Infosecurity Magazine (News)

Threat Score
88/100

Date Published: 2026-02-11

Date Updated: 2026-04-22

...
...

Google Cloud Mandiant attributes a campaign to UNC1069 (North Korea-linked) targeting fintech and cryptocurrency firms using hijacked Telegram profiles, social-engineered calendar invites to fake video calls (with reported deepfakes), and ClickFix-style ruses to trick macOS victims into executing commands. Attackers installed multiple backdoors (Waveshaper, Hypercall), information stealers and a data miner (Deepbreath, CHROMEPUSH) to exfiltrate Keychain credentials, browser data, Telegram and Notes data to facilitate cryptocurrency theft and future social engineering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.