The post The Next Phase of Crypto Hacks May Start With a Video Call appeared on BitcoinEthereumNews.com. A North Korea–nexus threat actor is enhancing its socialThe post The Next Phase of Crypto Hacks May Start With a Video Call appeared on BitcoinEthereumNews.com. A North Korea–nexus threat actor is enhancing its social

The Next Phase of Crypto Hacks May Start With a Video Call

A North Korea–nexus threat actor is enhancing its social engineering playbook. The group is integrating AI-enabled lures into crypto-focused hacks, according to a new report from Google’s Mandiant team.

The operation reflects a continued evolution in state-linked cyber activity targeting the digital asset sector, which saw a notable increase in 2025.

Sponsored

Sponsored

Fake Zoom Call Triggers Malware Attack on Crypto Firm 

In its latest report, Mandiant detailed its investigation into an intrusion targeting a FinTech company in the cryptocurrency sector. The attack was attributed to UNC1069. It is a financially motivated threat group active since at least 2018, with links to North Korea.

According to investigators, the intrusion began with a compromised Telegram account belonging to a crypto industry executive. The attackers used the hijacked profile to contact the victim. They gradually built trust before sending a Calendly invitation for a video meeting.

The meeting link directed the target to a fake Zoom domain hosted on infrastructure controlled by the threat actors. During the call, the victim reported seeing what appeared to be a deepfake video of a CEO from another cryptocurrency company. 

The attackers created the impression of audio problems in the meeting to justify the next step. They instructed the victim to run troubleshooting commands on their device.

Sponsored

Sponsored

Those commands, tailored for both macOS and Windows systems, secretly initiated the infection chain. This led to the deployment of multiple malware components.

Crypto Attack Flow From Social Engineering to Multi-Stage Malware Deployment. Source: Google 

Mandiant identified seven distinct malware families deployed during the intrusion. The tools were designed to steal Keychain credentials, extract browser cookies and login data, access Telegram session information, and collect other sensitive files. 

Investigators assessed that the objective was twofold: to enable potential cryptocurrency theft and harvest data that could support future social engineering attacks.

The investigation revealed an unusually large volume of tooling dropped onto a single host. This suggested a highly targeted effort to harvest as much data as possible from the compromised individual.

The incident is part of a broader pattern rather than a standalone case. In December 2025, BeInCrypto reported that North Korean-linked actors siphoned more than $300 million by posing as trusted industry figures during fraudulent Zoom and Microsoft Teams meetings.

The scale of activity throughout the year was even more striking. In total, North Korean threat groups were responsible for $2.02 billion in stolen digital assets in 2025, a 51% increase from the previous year.

Chainalysis also revealed that scam clusters tied on-chain to AI service providers show significantly higher operational efficiency than those without such links. According to the firm, this trend suggests a future in which AI becomes a standard component of most scam operations.

With AI tools growing more accessible and advanced, creating convincing deepfakes is easier than ever. The coming time will test whether the crypto sector can adapt its security fast enough to confront these advanced threats.

Source: https://beincrypto.com/north-korea-ai-crypto-hack-zoom-malware/

Market Opportunity
CyberConnect Logo
CyberConnect Price(CYBER)
$0.5264
$0.5264$0.5264
-1.57%
USD
CyberConnect (CYBER) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

The post American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight appeared on BitcoinEthereumNews.com. Key Takeaways: American Bitcoin (ABTC) surged nearly 85% on its Nasdaq debut, briefly reaching a $5B valuation. The Trump family, alongside Hut 8 Mining, controls 98% of the newly merged crypto-mining entity. Eric Trump called Bitcoin “modern-day gold,” predicting it could reach $1 million per coin. American Bitcoin, a fast-rising crypto mining firm with strong political and institutional backing, has officially entered Wall Street. After merging with Gryphon Digital Mining, the company made its Nasdaq debut under the ticker ABTC, instantly drawing global attention to both its stock performance and its bold vision for Bitcoin’s future. Read More: Trump-Backed Crypto Firm Eyes Asia for Bold Bitcoin Expansion Nasdaq Debut: An Explosive First Day ABTC’s first day of trading proved as dramatic as expected. Shares surged almost 85% at the open, touching a peak of $14 before settling at lower levels by the close. That initial spike valued the company around $5 billion, positioning it as one of 2025’s most-watched listings. At the last session, ABTC has been trading at $7.28 per share, which is a small positive 2.97% per day. Although the price has decelerated since opening highs, analysts note that the company has been off to a strong start and early investor activity is a hard-to-find feat in a newly-launched crypto mining business. According to market watchers, the listing comes at a time of new momentum in the digital asset markets. With Bitcoin trading above $110,000 this quarter, American Bitcoin’s entry comes at a time when both institutional investors and retail traders are showing heightened interest in exposure to Bitcoin-linked equities. Ownership Structure: Trump Family and Hut 8 at the Helm Its management and ownership set up has increased the visibility of the company. The Trump family and the Canadian mining giant Hut 8 Mining jointly own 98 percent…
Share
BitcoinEthereumNews2025/09/18 01:33
RWA Crypto Projects Gain Momentum with Chainlink, VeChain, and Avalanche Surging in Engagement

RWA Crypto Projects Gain Momentum with Chainlink, VeChain, and Avalanche Surging in Engagement

Phoenix Group published a report on the highest ranking RWA crypto projects on social activity, based on LunarCrush insights. Chainlink leads the rankings.
Share
Blockchainreporter2025/09/19 09:00
‘Compromise is in the air’: Ripple CLO signals progress on crypto bill

‘Compromise is in the air’: Ripple CLO signals progress on crypto bill

The post ‘Compromise is in the air’: Ripple CLO signals progress on crypto bill appeared on BitcoinEthereumNews.com. The White House made a second attempt to broker
Share
BitcoinEthereumNews2026/02/11 19:31