North Korean Hackers Target Crypto Firms with Fake Zoom Meetings
North Korea-linked threat actor UNC1069 has escalated its cyber operations against the cryptocurrency sector, deploying sophisticated social engineering tactics to infiltrate both Windows and macOS systems. The group, active since April 2018, has a documented history of masquerading as investors from reputable firms to orchestrate financial theft.
In a recent campaign detailed by Google Mandiant, attackers compromised a Telegram account belonging to a crypto executive, leveraging it to establish trust before delivering a malicious Calendly invitation. The fraudulent Zoom meeting link redirected victims to attacker-controlled infrastructure, where deepfake technology may have been employed to impersonate industry figures—a tactic previously observed in similar breaches.
The crypto industry remains a high-value target for state-sponsored actors seeking to exploit operational security gaps. While specific coins or exchanges weren't named in this incident, the attack underscores systemic vulnerabilities across decentralized finance infrastructure.