
Image by DC Studio, from Unsplash
Hackers Use Deepfake Zoom Call To Breach Crypto Firm
Hackers used a fake Zoom call with deepfakes to breach a crypto firm’s Mac system and steal crypto wallet data.
In a rush? Here are the quick facts:
- Hackers used deepfakes in a fake Zoom meeting.
- Victim was tricked via Telegram and a fake Calendly link.
- Malware targeted macOS with AppleScript and process injection.
Huntress cybersecurity firm detected an advanced cyberattack on June 11, 2025, when their partner reported suspicious activity from a Zoom extension. A state-sponsored North Korean hacking group, known as TA444, BlueNoroff, or Stardust Chollima, conducted an attack on a cryptocurrency foundation through deepfake video calls, and custom-built Mac malware.
The attack began weeks earlier when a staff member received an unexpected Telegram message that led them to a Google Meet link. The link redirected the user to a fake Zoom website, where they later participated in a deepfake-filled meeting. The system blocked their microphone, so they were prompted to download a malicious Zoom extension. The AppleScript file ‘zoom_sdk_support.scpt’ looked harmless, but it secretly installed malware in the background.
The malware disabled history logging while it installed Rosetta 2 for software compatibility, and then downloaded additional tools, which included backdoors, keyloggers, and cryptocurrency stealers. Huntress researchers detected eight different malicious files that specifically targeted macOS users through advanced process injection techniques, which are unusual for Apple systems.
Key components included “Telegram 2,” a persistent implant that enabled remote access; “Root Troy V4,” a full-featured backdoor; and “CryptoBot,” designed to search for and steal crypto wallet data from browsers. The hackers also used deepfake avatars to build trust and gather passwords.
The company advises organizations to be cautious of urgent meeting invites, last-minute platform changes, and requests to install unfamiliar extensions—especially from unknown contacts.