• bitcoinBitcoin (BTC) $ 60,385.00
  • ethereumEthereum (ETH) $ 1,617.45
  • tetherTether (USDT) $ 0.998474
  • bnbBNB (BNB) $ 560.65
  • usd-coinUSDC (USDC) $ 0.999644
  • xrpXRP (XRP) $ 1.06
  • solanaSolana (SOL) $ 75.42
  • tronTRON (TRX) $ 0.321272
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.05
  • hyperliquidHyperliquid (HYPE) $ 67.54
  • dogecoinDogecoin (DOGE) $ 0.073860
  • rainRain (RAIN) $ 0.015919
  • usdsUSDS (USDS) $ 0.999517
  • leo-tokenLEO Token (LEO) $ 9.56
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 411.76
  • stellarStellar (XLM) $ 0.176353
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 315.17
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • whitebitWhiteBIT Coin (WBT) $ 48.06
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • canton-networkCanton (CC) $ 0.144240
  • chainlinkChainlink (LINK) $ 7.45
  • cardanoCardano (ADA) $ 0.147134
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • labLAB (LAB) $ 15.01
  • usd1-wlfiUSD1 (USD1) $ 0.999056
  • daiDai (DAI) $ 0.999603
  • susdssUSDS (SUSDS) $ 1.08
  • ethena-usdeEthena USDe (USDE) $ 0.998121
  • the-open-networkGram (prev. Toncoin) (GRAM) $ 1.61
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • bitcoin-cashBitcoin Cash (BCH) $ 201.71
  • litecoinLitecoin (LTC) $ 43.29
  • hedera-hashgraphHedera (HBAR) $ 0.071884
  • wethWETH (WETH) $ 2,268.37
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • global-dollarGlobal Dollar (USDG) $ 0.999950
  • avalanche-2Avalanche (AVAX) $ 6.70
  • usdt0USDT0 (USDT0) $ 0.998824
  • suiSui (SUI) $ 0.704103
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • shiba-inuShiba Inu (SHIB) $ 0.000004
  • crypto-com-chainCronos (CRO) $ 0.054492
  • tether-goldTether Gold (XAUT) $ 4,009.14
  • nearNEAR Protocol (NEAR) $ 1.86
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bittensorBittensor (TAO) $ 208.68
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.059095
  • uniswapUniswap (UNI) $ 2.94
  • pax-goldPAX Gold (PAXG) $ 4,012.17
  • aster-2Aster (ASTER) $ 0.629049
  • okbOKB (OKB) $ 79.92
  • ripple-usdRipple USD (RLUSD) $ 0.999821
  • ondo-financeOndo (ONDO) $ 0.317861
  • htx-daoHTX DAO (HTX) $ 0.000002
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • worldcoin-wldWorldcoin (WLD) $ 0.425606
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • falcon-financeFalcon USD (USDF) $ 0.994751
  • mantleMantle (MNT) $ 0.429301
  • polkadotPolkadot (DOT) $ 0.828847
  • aaveAave (AAVE) $ 91.97
  • usddUSDD (USDD) $ 0.998358
  • bfusdBFUSD (BFUSD) $ 0.998706
  • pi-networkPi Network (PI) $ 0.117307
  • morphoMorpho (MORPHO) $ 1.90
  • skySky (SKY) $ 0.052689
  • internet-computerInternet Computer (ICP) $ 2.20
  • bitget-tokenBitget Token (BGB) $ 1.62
  • ethereum-classicEthereum Classic (ETC) $ 7.14
  • dexeDeXe (DEXE) $ 23.12
  • united-stablesUnited Stables (U) $ 0.999504
  • pepePepe (PEPE) $ 0.000002
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • blockchain-capitalBlockchain Capital (BCAP) $ 106.97
  • quant-networkQuant (QNT) $ 65.80
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.20
  • kucoin-sharesKuCoin (KCS) $ 6.93
  • stable-2​​Stable (STABLE) $ 0.038537
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.13
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • usdgoUSDGO (USDGO) $ 1.00
  • kaspaKaspa (KAS) $ 0.030194
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • render-tokenRender (RENDER) $ 1.57
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • cosmosCosmos Hub (ATOM) $ 1.54
  • audieraAudiera (BEAT) $ 2.78
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • memecoreMemeCore (M) $ 0.592132
  • algorandAlgorand (ALGO) $ 0.086189
  • wbnbWrapped BNB (WBNB) $ 759.61
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.071142
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • justJUST (JST) $ 0.087475
  • usdtbUSDtb (USDTB) $ 0.999452
  • nexoNEXO (NEXO) $ 0.732343
  • ethenaEthena (ENA) $ 0.078521
  • jupiter-exchange-solanaJupiter (JUP) $ 0.218283
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • gatechain-tokenGate (GT) $ 6.67
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.698187
  • beldexBeldex (BDX) $ 0.089821
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • adi-tokenADI (ADI) $ 5.51
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • velvetVelvet (VELVET) $ 1.62
  • venice-tokenVenice Token (VVV) $ 13.49
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.15
  • ghoGHO (GHO) $ 0.997826
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • pump-funPump.fun (PUMP) $ 0.001467
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • filecoinFilecoin (FIL) $ 0.736334
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • flare-networksFlare (FLR) $ 0.006594
  • yldsYLDS (YLDS) $ 0.999735
  • xdce-crowd-saleXDC Network (XDC) $ 0.028125
  • clbtcclBTC (CLBTC) $ 76,920.00
  • usual-usdUsual USD (USD0) $ 0.998430
  • midnight-3Midnight (NIGHT) $ 0.032156
  • usxUSX (USX) $ 0.999522
  • true-usdTrueUSD (TUSD) $ 0.997360
  • hash-2Provenance Blockchain (HASH) $ 0.008949
  • arbitrumArbitrum (ARB) $ 0.076998
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • a7a5A7A5 (A7A5) $ 0.012485
  • aptosAptos (APT) $ 0.586959
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • injective-protocolInjective (INJ) $ 4.70
  • tbtctBTC (TBTC) $ 70,942.00
  • lighterLighter (LIT) $ 1.82
  • aerodrome-financeAerodrome Finance (AERO) $ 0.460272
  • euro-coinEURC (EURC) $ 1.14
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.34
  • dashDash (DASH) $ 33.40
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.70
  • hastra-primePRIME (PRIME) $ 1.05
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • official-trumpOfficial Trump (TRUMP) $ 1.69
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.176569
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006266
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • vechainVeChain (VET) $ 0.004516
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • bonkBonk (BONK) $ 0.000004
  • cocaCOCA (COCA) $ 1.30
  • celestiaCelestia (TIA) $ 0.393124
  • jito-governance-tokenJito (JTO) $ 0.741206
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.546904
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.996624
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000061
  • sei-networkSei (SEI) $ 0.049866
  • spx6900SPX6900 (SPX) $ 0.358728
  • the9bitThe9bit (9BIT) $ 0.042627
  • ethgas-2ETHGas (GWEI) $ 0.155961
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • sun-tokenSun Token (SUN) $ 0.016723
  • ether-fiEther.fi (ETHFI) $ 0.340091
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • blockstackStacks (STX) $ 0.166763
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • kinesis-goldKinesis Gold (KAU) $ 128.17
  • unibaseUnibase (UB) $ 0.121788
  • apxusdapxUSD (APXUSD) $ 0.811489
  • curve-dao-tokenCurve DAO (CRV) $ 0.193600
  • pyth-networkPyth Network (PYTH) $ 0.036303
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • grassGrass (GRASS) $ 0.468079
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • gnosisGnosis (GNO) $ 108.02
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • tacTAC (TAC) $ 0.059282
  • plasmaPlasma (XPL) $ 0.106177
  • noonNoon (NOON) $ 0.751949
  • royal-dollarRoyal Dollar (RUSD) $ 0.998700
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • kite-2Kite (KITE) $ 0.117660
  • apenftAINFT (NFT) $ 0.00000026
  • bittorrentBitTorrent (BTT) $ 0.00000026
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • bitcoin-svBitcoin SV (BSV) $ 12.72
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • fraxLegacy Frax Dollar (FRAX) $ 0.990360
  • olympusOlympus (OHM) $ 15.70
  • pendlePendle (PENDLE) $ 1.37
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • tezosTezos (XTZ) $ 0.211349

How North Korean Hackers Turn Deepfake Zoom Calls Into Crypto Heists

0 3


A North Korea–nexus threat actor is enhancing its social engineering playbook. The group is integrating AI-enabled lures into crypto-focused hacks, according to a new report from Google’s Mandiant team.

The operation reflects a continued evolution in state-linked cyber activity targeting the digital asset sector, which saw a notable increase in 2025.

Fake Zoom Call Triggers Malware Attack on Crypto Firm

In its latest report, Mandiant detailed its investigation into an intrusion targeting a FinTech company in the cryptocurrency sector. The attack was attributed to UNC1069. It is a financially motivated threat group active since at least 2018, with links to North Korea.

“Mandiant has observed this threat actor evolve its tactics, techniques, and procedures (TTPs), tooling, and targeting. Since at least 2023, the group has shifted from spear-phishing techniques and traditional finance (TradFi) targeting towards the Web3 industry, such as centralized exchanges (CEX), software developers at financial institutions, high-technology companies, and individuals at venture capital funds,” the report read.

According to investigators, the intrusion began with a compromised Telegram account belonging to a crypto industry executive. The attackers used the hijacked profile to contact the victim. They gradually built trust before sending a Calendly invitation for a video meeting.

The meeting link directed the target to a fake Zoom domain hosted on infrastructure controlled by the threat actors. During the call, the victim reported seeing what appeared to be a deepfake video of a CEO from another cryptocurrency company.

“While Mandiant was unable to recover forensic evidence to independently verify the use of AI models in this specific instance, the reported ruse is similar to a previously publicly reported incident with similar characteristics, where deepfakes were also allegedly used,” the report added.

The attackers created the impression of audio problems in the meeting to justify the next step. They instructed the victim to run troubleshooting commands on their device.

Those commands, tailored for both macOS and Windows systems, secretly initiated the infection chain. This led to the deployment of multiple malware components.

Crypto Attack Flow From Social Engineering to Multi-Stage Malware Deployment. Source: Google

Crypto Attack Flow From Social Engineering to Multi-Stage Malware Deployment. Source: Google

Mandiant identified seven distinct malware families deployed during the intrusion. The tools were designed to steal Keychain credentials, extract browser cookies and login data, access Telegram session information, and collect other sensitive files.

Investigators assessed that the objective was twofold: to enable potential cryptocurrency theft and harvest data that could support future social engineering attacks.

The investigation revealed an unusually large volume of tooling dropped onto a single host. This suggested a highly targeted effort to harvest as much data as possible from the compromised individual.

The incident is part of a broader pattern rather than a standalone case. In December 2025, BeInCrypto reported that North Korean-linked actors siphoned more than $300 million by posing as trusted industry figures during fraudulent Zoom and Microsoft Teams meetings.

The scale of activity throughout the year was even more striking. In total, North Korean threat groups were responsible for $2.02 billion in stolen digital assets in 2025, a 51% increase from the previous year.

Chainalysis also revealed that scam clusters tied on-chain to AI service providers show significantly higher operational efficiency than those without such links. According to the firm, this trend suggests a future in which AI becomes a standard component of most scam operations.

With AI tools growing more accessible and advanced, creating convincing deepfakes is easier than ever. The coming time will test whether the crypto sector can adapt its security fast enough to confront these advanced threats.

The post How North Korean Hackers Turn Deepfake Zoom Calls Into Crypto Heists appeared first on BeInCrypto.



Source link

Leave A Reply

Your email address will not be published.