• bitcoinBitcoin (BTC) $ 88,297.00
  • ethereumEthereum (ETH) $ 2,927.48
  • tetherTether (USDT) $ 0.998810
  • bnbBNB (BNB) $ 882.94
  • xrpXRP (XRP) $ 1.90
  • usd-coinUSDC (USDC) $ 0.999689
  • solanaSolana (SOL) $ 123.97
  • jusdJUSD (JUSD) $ 0.999053
  • tronTRON (TRX) $ 0.295324
  • staked-etherLido Staked Ether (STETH) $ 2,924.95
  • dogecoinDogecoin (DOGE) $ 0.122075
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • cardanoCardano (ADA) $ 0.350800
  • wrapped-stethWrapped stETH (WSTETH) $ 3,586.16
  • bitcoin-cashBitcoin Cash (BCH) $ 589.39
  • whitebitWhiteBIT Coin (WBT) $ 53.72
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 88,032.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,186.69
  • wrapped-eethWrapped eETH (WEETH) $ 3,180.03
  • usdsUSDS (USDS) $ 0.999414
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998765
  • moneroMonero (XMR) $ 469.33
  • chainlinkChainlink (LINK) $ 11.94
  • leo-tokenLEO Token (LEO) $ 9.15
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 88,237.00
  • wethWETH (WETH) $ 2,926.07
  • stellarStellar (XLM) $ 0.206261
  • ethena-usdeEthena USDe (USDE) $ 0.998877
  • hyperliquidHyperliquid (HYPE) $ 27.13
  • zcashZcash (ZEC) $ 371.79
  • canton-networkCanton (CC) $ 0.155752
  • suiSui (SUI) $ 1.43
  • litecoinLitecoin (LTC) $ 69.15
  • avalanche-2Avalanche (AVAX) $ 11.72
  • usd1-wlfiUSD1 (USD1) $ 0.999488
  • usdt0USDT0 (USDT0) $ 0.998874
  • hedera-hashgraphHedera (HBAR) $ 0.106181
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • daiDai (DAI) $ 0.999750
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.157556
  • susdssUSDS (SUSDS) $ 1.09
  • paypal-usdPayPal USD (PYUSD) $ 0.999917
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • the-open-networkToncoin (TON) $ 1.51
  • crypto-com-chainCronos (CRO) $ 0.090619
  • rainRain (RAIN) $ 0.009936
  • polkadotPolkadot (DOT) $ 1.86
  • uniswapUniswap (UNI) $ 4.68
  • mantleMantle (MNT) $ 0.871675
  • memecoreMemeCore (M) $ 1.57
  • tether-goldTether Gold (XAUT) $ 5,077.59
  • bitget-tokenBitget Token (BGB) $ 3.60
  • aaveAave (AAVE) $ 153.75
  • bittensorBittensor (TAO) $ 230.99
  • okbOKB (OKB) $ 103.93
  • falcon-financeFalcon USD (USDF) $ 0.996105
  • pepePepe (PEPE) $ 0.000005
  • pax-goldPAX Gold (PAXG) $ 5,093.16
  • nearNEAR Protocol (NEAR) $ 1.47
  • internet-computerInternet Computer (ICP) $ 3.28
  • jito-staked-solJito Staked SOL (JITOSOL) $ 155.87
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,924.80
  • ethereum-classicEthereum Classic (ETC) $ 11.36
  • pump-funPump.fun (PUMP) $ 0.002972
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • htx-daoHTX DAO (HTX) $ 0.000002
  • ondo-financeOndo (ONDO) $ 0.333589
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • global-dollarGlobal Dollar (USDG) $ 0.999572
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,109.59
  • aster-2Aster (ASTER) $ 0.639090
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.55
  • hash-2Provenance Blockchain (HASH) $ 0.027394
  • pi-networkPi Network (PI) $ 0.172705
  • skySky (SKY) $ 0.062950
  • kucoin-sharesKuCoin (KCS) $ 10.75
  • riverRiver (RIVER) $ 71.72
  • ripple-usdRipple USD (RLUSD) $ 0.999653
  • binance-staked-solBinance Staked SOL (BNSOL) $ 135.75
  • ethenaEthena (ENA) $ 0.167364
  • wbnbWrapped BNB (WBNB) $ 882.10
  • bfusdBFUSD (BFUSD) $ 0.998085
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999578
  • worldcoin-wldWorldcoin (WLD) $ 0.453668
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.117842
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,383.85
  • aptosAptos (APT) $ 1.54
  • gatechain-tokenGate (GT) $ 9.84
  • usddUSDD (USDD) $ 0.998668
  • cosmosCosmos Hub (ATOM) $ 2.22
  • myx-financeMYX Finance (MYX) $ 5.66
  • algorandAlgorand (ALGO) $ 0.120606
  • quant-networkQuant (QNT) $ 73.45
  • kaspaKaspa (KAS) $ 0.039408
  • arbitrumArbitrum (ARB) $ 0.168840
  • midnight-3Midnight (NIGHT) $ 0.059233
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 88,547.00
  • render-tokenRender (RENDER) $ 1.88
  • ignition-fbtcFunction FBTC (FBTC) $ 88,533.00
  • official-trumpOfficial Trump (TRUMP) $ 4.77
  • filecoinFilecoin (FIL) $ 1.27
  • nexoNEXO (NEXO) $ 0.934046
  • flare-networksFlare (FLR) $ 0.010570
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999610
  • vechainVeChain (VET) $ 0.010075
  • usdtbUSDtb (USDTB) $ 0.999779
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,172.52
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.97
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 88,072.00
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,114.18
  • dashDash (DASH) $ 61.19
  • bonkBonk (BONK) $ 0.000009
  • wrappedm-by-m0WrappedM by M0 (WM) $ 0.999451
  • xdce-crowd-saleXDC Network (XDC) $ 0.039218
  • story-2Story (IP) $ 2.11
  • ousgOUSG (OUSG) $ 114.09
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • sei-networkSei (SEI) $ 0.105410
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 88,026.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,129.22
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,111.21
  • morphoMorpho (MORPHO) $ 1.23
  • clbtcclBTC (CLBTC) $ 86,786.00
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999547
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.24
  • usdaiUSDai (USDAI) $ 0.999448
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.89
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,924.79
  • jupiter-exchange-solanaJupiter (JUP) $ 0.191732
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 27.40
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.90
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 144.37
  • wrapped-flareWrapped Flare (WFLR) $ 0.010572
  • beldexBeldex (BDX) $ 0.079150
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.009580
  • tezosTezos (XTZ) $ 0.558277
  • usual-usdUsual USD (USD0) $ 0.994276
  • optimismOptimism (OP) $ 0.294469
  • chilizChiliz (CHZ) $ 0.055734
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,929.10
  • blockstackStacks (STX) $ 0.298457
  • c8ntinuumc8ntinuum (CTM) $ 0.120183
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.798313
  • tbtctBTC (TBTC) $ 88,047.00
  • a7a5A7A5 (A7A5) $ 0.013183
  • curve-dao-tokenCurve DAO (CRV) $ 0.344794
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.220207
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.09
  • ghoGHO (GHO) $ 0.999518
  • true-usdTrueUSD (TUSD) $ 0.998824
  • gtethGTETH (GTETH) $ 2,925.64
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997518
  • fasttokenFasttoken (FTN) $ 1.09
  • lighterLighter (LIT) $ 1.85
  • axie-infinityAxie Infinity (AXS) $ 2.67
  • injective-protocolInjective (INJ) $ 4.41
  • lido-daoLido DAO (LDO) $ 0.513534
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,150.22
  • kaiaKaia (KAIA) $ 0.074039
  • cap-usdCap USD (CUSD) $ 1.00
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • msolMarinade Staked SOL (MSOL) $ 167.85
  • sbtc-2sBTC (SBTC) $ 92,512.00
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,279.17
  • ether-fiEther.fi (ETHFI) $ 0.592474
  • doublezeroDoubleZero (2Z) $ 0.117902
  • aerodrome-financeAerodrome Finance (AERO) $ 0.448648
  • justJUST (JST) $ 0.046358
  • kinesis-silverKinesis Silver (KAG) $ 109.37
  • newton-projectAB (AB) $ 0.004115
  • stader-ethxStader ETHx (ETHX) $ 3,157.81
  • usdbUSDB (USDB) $ 0.992260
  • flokiFLOKI (FLOKI) $ 0.000041
  • layerzeroLayerZero (ZRO) $ 1.97
  • resolv-usrResolv USR (USR) $ 0.999848
  • bittorrentBitTorrent (BTT) $ 0.00000040
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • kinesis-goldKinesis Gold (KAU) $ 162.92
  • syrupMaple Finance (SYRUP) $ 0.335887
  • staked-aaveStaked Aave (STKAAVE) $ 152.46
  • the-graphThe Graph (GRT) $ 0.035814
  • celestiaCelestia (TIA) $ 0.439232
  • euro-coinEURC (EURC) $ 1.19
  • stable-2​​Stable (STABLE) $ 0.021218
  • gnosisGnosis (GNO) $ 139.60
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.181566
  • iotaIOTA (IOTA) $ 0.085271
  • decredDecred (DCR) $ 21.09
  • sun-tokenSun Token (SUN) $ 0.018584
  • starknetStarknet (STRK) $ 0.068534
  • bitcoin-svBitcoin SV (BSV) $ 17.77
  • spx6900SPX6900 (SPX) $ 0.377389
  • the-sandboxThe Sandbox (SAND) $ 0.131545
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.843867
  • apenftAINFT (NFT) $ 0.00000035
  • crvusdcrvUSD (CRVUSD) $ 1.00
  • conflux-tokenConflux (CFX) $ 0.067177

North Korea–Linked Hackers Use Deepfake Video Calls to Target Crypto Workers

0 1

North Korea–Linked Hackers Use Deepfake Video Calls to Target Crypto Workers

North Korea-linked hackers continue to use live video calls, including AI-generated deepfakes, to trick crypto developers and workers into installing malicious software on their own devices.

In the latest instance disclosed by BTC Prague co-founder Martin Kuchař, attackers used a compromised Telegram account and a staged video call to push malware disguised as a Zoom audio fix, he said.

The “high-level hacking campaign” appears to be “targeting Bitcoin and crypto users,” Kuchař disclosed Thursday on X.



Attackers contact the victim and set up a Zoom or Teams call, Kuchař explained. During the call, they use an AI-generated video to appear as someone the victim knows.

They then claim there is an audio problem and ask the victim to install a plugin or file to fix it. Once installed, the malware grants attackers full system access, allowing them to steal Bitcoin, take over Telegram accounts, and use those accounts to target others.

It comes as AI-driven impersonation scams have pushed crypto-related losses to a record $17 billion in 2025, with attackers increasingly using deepfake video, voice cloning, and fake identities to deceive victims and gain access to funds, according to data from blockchain analytics firm Chainalysis.

Similar attacks

The attack, as described by Kuchař, closely matches a technique first documented by cybersecurity company Huntress, which reported in July last year that these attackers lure a target crypto worker into a staged Zoom call after initial contact on Telegram, often using a fake meeting link hosted on a spoofed Zoom domain.

During the call, the attackers would claim there is an audio problem and instruct the victim to install what appears to be a Zoom-related fix, which is actually a malicious AppleScript that initiates a multi-stage macOS infection, according to Huntress.

Once executed, the script disables shell history, checks for or installs Rosetta 2 (a translation layer) on Apple Silicon devices, and repeatedly prompts the user for their system password to gain elevated privileges.

The study found that malware chain installs multiple payloads, including persistent backdoors, keylogging and clipboard tools, and crypto wallet stealers, a similar sequence Kuchař pointed to when he disclosed on Monday that his Telegram account was compromised and later used to target others in the same way.

Social patterns

Security researchers at Huntress have attributed the intrusion with high confidence to a North Korea-linked advanced persistent threat tracked as TA444, also known as BlueNoroff and by several other aliases operating under the umbrella term Lazarus Group, a state-sponsored group focused on cryptocurrency theft since at least 2017.

When asked about the operational goals of these campaigns and whether they think there’s a correlation, Shān Zhang, chief information security officer at blockchain security firm Slowmist, told Decrypt that the latest attack on Kuchař is “possibly” connected to broader campaigns from the Lazarus Group.

“There is clear reuse across campaigns. We consistently see targeting of specific wallets and the use of very similar install scripts,” David Liberman, co-creator of decentralized AI compute network Gonka, told Decrypt.

Images and video “can no longer be treated as reliable proof of authenticity,” Liberman said, adding that digital content “should be cryptographically signed by its creator, and such signatures should require multi-factor authorization.”

Narratives, in contexts such as this, have become “an important signal to track and detect” given how these attacks “rely on familiar social patterns,” he said.

North Korea’s Lazarus Group is tied to campaigns against crypto firms, workers, and developers, using tailored malware and sophisticated social engineering to steal digital assets and access credentials.

Source

Leave A Reply

Your email address will not be published.