North Korea-linked hackers continue to use live video calls, including AI-generated deepfakes, to trick crypto developers and workers into installing malicious software on their own devices.
In the latest instance disclosed by BTC Prague co-founder Martin Kuchař, attackers used a compromised Telegram account and a staged video call to push malware disguised as a Zoom audio fix, he said.
They then claim there is an audio problem and ask the victim to install a plugin or file to fix it. Once installed, the malware grants attackers full system access, allowing them to steal Bitcoin, take over Telegram accounts, and use those accounts to target others.
During the call, the attackers would claim there is an audio problem and instruct the victim to install what appears to be a Zoom-related fix, which is actually a malicious AppleScript that initiates a multi-stage macOS infection, according to Huntress.
Once executed, the script disables shell history, checks for or installs Rosetta 2 (a translation layer) on Apple Silicon devices, and repeatedly prompts the user for their system password to gain elevated privileges.
When asked about the operational goals of these campaigns and whether they think there’s a correlation, Shān Zhang, chief information security officer at blockchain security firm Slowmist, told Decrypt that the latest attack on Kuchař is “possibly” connected to broader campaigns from the Lazarus Group.
“There is clear reuse across campaigns. We consistently see targeting of specific wallets and the use of very similar install scripts,” David Liberman, co-creator of decentralized AI compute network Gonka, told Decrypt.
Images and video “can no longer be treated as reliable proof of authenticity,” Liberman said, adding that digital content “should be cryptographically signed by its creator, and such signatures should require multi-factor authorization.”
Narratives, in contexts such as this, have become “an important signal to track and detect” given how these attacks “rely on familiar social patterns,” he said.


















