Skip to content

Bitcoin Targeted by North Korean Deepfakes

North Korea’s BlueNoroff Uses Deepfakes to Target Crypto Workers

  • Attackers use fake video calls and a Zoom “audio fix” to deliver macOS malware.
  • The technique is linked to North Korea’s BlueNoroff, part of the Lazarus Group.
  • AI-driven impersonation scams have led to crypto losses reaching $17 billion in 2025.
  • Martin Kuchař revealed that attackers used compromised Telegram accounts for staging malware attacks.
  • The malware grants full system access, enabling theft of Bitcoin and other digital assets.

North Korea-linked hackers continue to exploit AI-generated deepfakes in sophisticated social engineering campaigns targeting cryptocurrency developers and workers. These attacks involve staged video calls where victims are tricked into installing malicious software under the guise of fixing audio issues on platforms like Zoom or Teams.

Such tactics have significantly contributed to record crypto losses, highlighting the need for heightened security measures against advanced persistent threats like the Lazarus Group. (Source)

Share