Skip to content
NetarxImpact Database
Deepfake Video CallConfirmed AI-enabledConfirmed

Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware

An unnamed cryptocurrency company executive · Cryptocurrency · Unknown · February 2026

What happened

Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.

How the deception worked

Trust was borrowed twice over. The initial contact came from the genuine, compromised Telegram account of a crypto executive the target knew, and the meeting itself opened with what looked like a familiar CEO on camera, so two independent-seeming signals both confirmed the caller was real. Mid-call the attackers claimed the victim had an audio problem and offered to help, supplying troubleshooting commands to paste and run, the ClickFix pattern. One embedded command launched the infection chain on the victim's Mac. The resulting toolset harvested credentials, browser data, Telegram material and keystrokes, both to enable cryptocurrency theft and to turn the new victim's identity into the next campaign's opening move.

AI involvement · Confirmed AI-enabled

Mandiant reported the attackers presented a deepfake video during the Zoom call before pivoting to a fake audio-troubleshooting fix.

The control that would have caught it· our reading, not a claim from the sources

No meeting should ever require running shell commands to fix audio, and video identity plus a known messenger account are no longer sufficient verification for a high-value request; confirm on a separate, pre-established channel.

Sources (2)

  1. North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam
    The Record (Recorded Future News)·therecord.mediaOpen ↗
  2. North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms
    Infosecurity Magazine·infosecurity-magazine.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.