{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos"},"incident":{"title":"BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware","date":"2025-06","date_precision":"month","victim_org":"Employee of a cryptocurrency foundation (Web3 sector)","sector":"Cryptocurrency","country":"United States","primary_vector":"Deepfake Video Call","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Huntress researchers reported the victim joined a group video call populated by deepfaked versions of their own company's senior leadership and external participants, who then instructed them to install a malicious 'Zoom extension'.","outcomes":["Cryptocurrency Theft","Credential Theft","Espionage"],"loss_usd":null,"loss_note":"Amount stolen not disclosed","records_affected":null,"threat_actor":"BlueNoroff (also tracked as TA444, Sapphire Sleet, APT38; DPRK-aligned)","summary":"In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.","how_it_worked":"The operation was patient: an initial Telegram approach for a business meeting, a scheduling link that looked routine, and a delay of weeks so the eventual call felt like a long-arranged commitment rather than a fresh lure. The deepfaked participants included the victim's own leadership, which is the strongest possible trust signal on a call and removed any impulse to verify. The malware delivery was then disguised as ordinary meeting friction: the target's microphone was not working, and everyone in the meeting was waiting. Fixing a technical problem so as not to hold up senior colleagues reframed installing an unsigned extension as courtesy rather than risk.","lessons":"Meeting software should never be extended from links supplied in-call; blocking unsigned script execution and requiring installs to come from a managed software catalogue removes the payload step entirely.","confidence":"Confirmed","sources":[{"title":"North Korean hackers deepfake execs in Zoom call to spread Mac malware","url":"https://www.bleepingcomputer.com/news/security/north-korean-hackers-deepfake-execs-in-zoom-call-to-spread-mac-malware/","publisher":"BleepingComputer"},{"title":"BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware","url":"https://thehackernews.com/2025/06/bluenoroff-deepfake-zoom-scam-hits.html","publisher":"The Hacker News"}],"entry_type":"incident","slug":"2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bluenoroff-uses-deepfaked-executives-on-a-fake-zoom-call-to-plant-macos"}}