DeFi Daily News
Tuesday, January 27, 2026
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Web 3

rewrite this title North Korea–Linked Hackers Use Deepfake Video Calls to Target Crypto Workers – Decrypt

Vince Dioquino by Vince Dioquino
January 26, 2026
in Web 3
0 0
0
rewrite this title North Korea–Linked Hackers Use Deepfake Video Calls to Target Crypto Workers – Decrypt
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

In brief

Attackers have used a fake video call and a Zoom “audio fix” to deliver macOS malware.
The method matches a previously documented intrusion method tied to North Korea’s BlueNoroff, a Lazarus sub-group.
The incident comes as AI-driven impersonation scams pushed crypto losses to a record $17 billion in 2025.

North Korea-linked hackers continue to use live video calls, including AI-generated deepfakes, to trick crypto developers and workers into installing malicious software on their own devices.

In the latest instance disclosed by BTC Prague co-founder Martin Kuchař, attackers used a compromised Telegram account and a staged video call to push malware disguised as a Zoom audio fix, he said.

The “high-level hacking campaign” appears to be “targeting Bitcoin and crypto users,” Kuchař disclosed Thursday on X.



Attackers contact the victim and set up a Zoom or Teams call, Kuchař explained. During the call, they use an AI-generated video to appear as someone the victim knows.

They then claim there is an audio problem and ask the victim to install a plugin or file to fix it. Once installed, the malware grants attackers full system access, allowing them to steal Bitcoin, take over Telegram accounts, and use those accounts to target others.

It comes as AI-driven impersonation scams have pushed crypto-related losses to a record $17 billion in 2025, with attackers increasingly using deepfake video, voice cloning, and fake identities to deceive victims and gain access to funds, according to data from blockchain analytics firm Chainalysis.

Similar attacks

The attack, as described by Kuchař, closely matches a technique first documented by cybersecurity company Huntress, which reported in July last year that these attackers lure a target crypto worker into a staged Zoom call after initial contact on Telegram, often using a fake meeting link hosted on a spoofed Zoom domain.

During the call, the attackers would claim there is an audio problem and instruct the victim to install what appears to be a Zoom-related fix, which is actually a malicious AppleScript that initiates a multi-stage macOS infection, according to Huntress.

Once executed, the script disables shell history, checks for or installs Rosetta 2 (a translation layer) on Apple Silicon devices, and repeatedly prompts the user for their system password to gain elevated privileges.

The study found that malware chain installs multiple payloads, including persistent backdoors, keylogging and clipboard tools, and crypto wallet stealers, a similar sequence Kuchař pointed to when he disclosed on Monday that his Telegram account was compromised and later used to target others in the same way.

Social patterns

Security researchers at Huntress have attributed the intrusion with high confidence to a North Korea-linked advanced persistent threat tracked as TA444, also known as BlueNoroff and by several other aliases operating under the umbrella term Lazarus Group, a state-sponsored group focused on cryptocurrency theft since at least 2017.

When asked about the operational goals of these campaigns and whether they think there’s a correlation, Shān Zhang, chief information security officer at blockchain security firm Slowmist, told Decrypt that the latest attack on Kuchař is “possibly” connected to broader campaigns from the Lazarus Group.

“No single indicator is decisive on its own; it’s the combination that matters,” Zhang said.”Deepfake-enabled lures typically rely on new or disposable meeting accounts and look-alike Zoom or Teams links, and the call quickly becomes highly scripted.”Attackers “create urgency and push the target” to install the so-called “Zoom/Teams fix” early in the conversation, he explained.

“There is clear reuse across campaigns. We consistently see targeting of specific wallets and the use of very similar install scripts,” David Liberman, co-creator of decentralized AI compute network Gonka, told Decrypt.

Images and video “can no longer be treated as reliable proof of authenticity,” Liberman said, adding that digital content “should be cryptographically signed by its creator, and such signatures should require multi-factor authorization.”

Narratives, in contexts such as this, have become “an important signal to track and detect,” given how these attacks “rely on familiar social patterns,” he said.

North Korea’s Lazarus Group is tied to campaigns against crypto firms, workers, and developers, using tailored malware and sophisticated social engineering to steal digital assets and access credentials.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: CallsCryptoDecryptdeepfakeHackersKorealinkedNorthrewritetargettitlevideoworkers
ShareTweetShare
Previous Post

And were back!

Next Post

rewrite this title California Gov. Gavin Newsom says he will launch a review into whether TikTok is violating state law by censoring content critical of President Donald Trump (Tyler Katzenberger/Politico)

Next Post
rewrite this title California Gov. Gavin Newsom says he will launch a review into whether TikTok is violating state law by censoring content critical of President Donald Trump (Tyler Katzenberger/Politico)

rewrite this title California Gov. Gavin Newsom says he will launch a review into whether TikTok is violating state law by censoring content critical of President Donald Trump (Tyler Katzenberger/Politico)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title The Next Wave of Crypto: An Exclusive Podcast with Yat Siu

rewrite this title The Next Wave of Crypto: An Exclusive Podcast with Yat Siu

May 30, 2025
Sen. Mitch McConnell falls in Capitol hallway

Sen. Mitch McConnell falls in Capitol hallway

October 16, 2025
3 gold stocks to consider, building wealth amid uncertainties, student loan defaults

3 gold stocks to consider, building wealth amid uncertainties, student loan defaults

May 5, 2025
rewrite this title and make it good for SEO Best Meme Coins 2025: Top Picks for the New Crypto Year – NFT Plazas

rewrite this title and make it good for SEO Best Meme Coins 2025: Top Picks for the New Crypto Year – NFT Plazas

December 15, 2025
Boulder attack update: Victim dies from injuries, charges upgraded

Boulder attack update: Victim dies from injuries, charges upgraded

June 30, 2025
rewrite this title Ethereum Treasuries “Propped Up” By  Billion In Korean Retail Money, Says Crypto Founder | Bitcoinist.com

rewrite this title Ethereum Treasuries “Propped Up” By $6 Billion In Korean Retail Money, Says Crypto Founder | Bitcoinist.com

October 7, 2025
rewrite this title NBA goes chalk with Rising Stars rookie team

rewrite this title NBA goes chalk with Rising Stars rookie team

January 26, 2026
rewrite this title California Gov. Gavin Newsom says he will launch a review into whether TikTok is violating state law by censoring content critical of President Donald Trump (Tyler Katzenberger/Politico)

rewrite this title California Gov. Gavin Newsom says he will launch a review into whether TikTok is violating state law by censoring content critical of President Donald Trump (Tyler Katzenberger/Politico)

January 26, 2026
rewrite this title North Korea–Linked Hackers Use Deepfake Video Calls to Target Crypto Workers – Decrypt

rewrite this title North Korea–Linked Hackers Use Deepfake Video Calls to Target Crypto Workers – Decrypt

January 26, 2026
And were back!

And were back!

January 26, 2026
rewrite this title Week 4: A Peek Into This Past Week + What I’m Reading, Listening to, and Watching!

rewrite this title Week 4: A Peek Into This Past Week + What I’m Reading, Listening to, and Watching!

January 26, 2026
rewrite this title FinovateEurope 2026: Innovation, Regulation, and Transformation in the AI Era – Finovate

rewrite this title FinovateEurope 2026: Innovation, Regulation, and Transformation in the AI Era – Finovate

January 26, 2026
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.