Skip to content
NetarxImpact Database
Deepfake Video CallConfirmed AI-enabledConfirmed

BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware

Employee of a cryptocurrency foundation (Web3 sector) · Cryptocurrency · United States · June 2025

What happened

In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.

How the deception worked

The operation was patient: an initial Telegram approach for a business meeting, a scheduling link that looked routine, and a delay of weeks so the eventual call felt like a long-arranged commitment rather than a fresh lure. The deepfaked participants included the victim's own leadership, which is the strongest possible trust signal on a call and removed any impulse to verify. The malware delivery was then disguised as ordinary meeting friction: the target's microphone was not working, and everyone in the meeting was waiting. Fixing a technical problem so as not to hold up senior colleagues reframed installing an unsigned extension as courtesy rather than risk.

AI involvement · Confirmed AI-enabled

Huntress researchers reported the victim joined a group video call populated by deepfaked versions of their own company's senior leadership and external participants, who then instructed them to install a malicious 'Zoom extension'.

The control that would have caught it· our reading, not a claim from the sources

Meeting software should never be extended from links supplied in-call; blocking unsigned script execution and requiring installs to come from a managed software catalogue removes the payload step entirely.

Sources (2)

  1. North Korean hackers deepfake execs in Zoom call to spread Mac malware
    BleepingComputer·bleepingcomputer.comOpen ↗
  2. BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware
    The Hacker News·thehackernews.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.