Inside North Korea’s New Deepfake Crypto Scam

North Korean crypto hackers are refining a familiar scam. They once relied on fake job offers and investment pitches to spread malware — now their methods are becoming more sophisticated.

Previously, these attacks depended on victims interacting directly with infected files. But tighter coordination among hacker groups has allowed them to overcome this weakness, using recycled video calls and impersonations of Web3 executives to deceive targets.

Sponsored

Sponsored

North Korea — A Crypto Hacking Pioneer

North Korean crypto hackers are already a global menace, but their infiltration tactics have significantly evolved.

Whereas these criminals used to only seek employment in Web3 firms, they’ve been using fake job offers to spread malware more recently. Now, this plan is expanding again.

According to reports from Kaspersky, a digital security firm, these North Korean crypto hackers are employing new tools.

BlueNoroff APT, a sub-branch of Lazarus Group, the most feared DPRK-based criminal organization, has two such active campaigns. Dubbed GhostCall and GhostHire, both share the same management infrastructure.

Novel Tactics Explained

In GhostCall, these North Korean crypto hackers will target Web3 executives, posing as potential investors. GhostHire, on the other hand, attracts blockchain engineers with tempting job offers. Both tactics have been in use since last month at the latest, but the threat has been increasing.

Sponsored

Sponsored

Whoever the target is, the actual scam is the same: they trick a prospective mark into downloading malware, whether it be a phony “coding challenge” or a clone of Zoom or Microsoft Teams.

Either way, the victim only needs to engage with this trapped platform, at which point the North Korean crypto hackers can compromise their systems.

Kaspersky noted a series of marginal improvements, like focusing on crypto developers’ preferred operating systems. The scams have a common point of failure: the victim has to actually interact with suspicious software.

This has harmed previous scams’ success rate, but these North Korean hackers have found a new way to recycle lost opportunities.

Turning Failures into New Weapons

Specifically, the enhanced coordination between GhostCall and GhostHire has enabled hackers to improve their social engineering. In addition to AI-generated content, they can also use hacked accounts from genuine entrepreneurs or fragments of real video calls to make their scams believable.

One can only imagine how dangerous this is. A crypto executive might cut off contact with a suspicious recruiter or investor, only to have their likeness later weaponized against new victims.

Using AI, hackers can synthesize new “conversations” that mimic a person’s tone, gestures, and surroundings with alarming realism.

Even when these scams fail, the potential damage remains severe. Anyone approached under unusual or high-pressure circumstances should stay vigilant—never download unfamiliar software or engage with requests that seem out of place.

Source link

Landon Manning

https://beincrypto.com/north-korea-deepfake-crypto-scam-lazarus/

2025-10-28 21:00:00

bitcoin
Bitcoin (BTC) $ 91,246.00 0.65%
ethereum
Ethereum (ETH) $ 3,008.84 0.04%
tether
Tether (USDT) $ 1.00 0.01%
xrp
XRP (XRP) $ 2.19 0.61%
bnb
BNB (BNB) $ 877.94 0.28%
usd-coin
USDC (USDC) $ 0.9997 0.01%
solana
Wrapped SOL (SOL) $ 136.78 0.13%
tron
TRON (TRX) $ 0.281001 0.10%
staked-ether
Lido Staked Ether (STETH) $ 3,009.89 0.08%
dogecoin
Dogecoin (DOGE) $ 0.149302 0.03%
cardano
Cardano (ADA) $ 0.418737 0.86%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03 1.43%
whitebit
WhiteBIT Coin (WBT) $ 58.76 0.29%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,671.60 0.02%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 90,936.00 0.57%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,259.96 0.03%
bitcoin-cash
Bitcoin Cash (BCH) $ 524.36 1.23%
usds
USDS (USDS) $ 1.00 0.03%
hyperliquid
Hyperliquid (HYPE) $ 34.05 3.71%
chainlink
Chainlink (LINK) $ 13.05 0.16%
leo-token
LEO Token (LEO) $ 9.85 0.54%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999774 0.05%
stellar
Stellar (XLM) $ 0.253069 0.38%
weth
WETH (WETH) $ 3,010.14 0.09%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,256.03 0.07%
monero
Monero (XMR) $ 416.45 1.40%
zcash
Zcash (ZEC) $ 458.99 1.65%
ethena-usde
Ethena USDe (USDE) $ 0.999573 0.00%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 91,228.00 0.69%
litecoin
Litecoin (LTC) $ 84.27 0.09%
hedera-hashgraph
Hedera (HBAR) $ 0.14278 0.62%
avalanche-2
Avalanche (AVAX) $ 14.17 3.75%
sui
Sui (SUI) $ 1.53 2.17%
shiba-inu
Shiba Inu (SHIB) $ 0.000009 0.13%
dai
Dai (DAI) $ 0.9994 0.01%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.159376 0.61%
susds
sUSDS (SUSDS) $ 1.08 0.49%
crypto-com-chain
Cronos (CRO) $ 0.108059 0.05%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21 0.02%
uniswap
Uniswap (UNI) $ 6.21 1.48%
the-open-network
Toncoin (TON) $ 1.56 1.59%
paypal-usd
PayPal USD (PYUSD) $ 0.999818 0.02%
polkadot
Polkadot (DOT) $ 2.27 0.05%
usdt0
USDT0 (USDT0) $ 1.00 0.00%
mantle
Mantle (MNT) $ 1.10 2.15%
canton-network
Canton (CC) $ 0.086345 4.75%
bittensor
Bittensor (TAO) $ 294.25 0.93%
aave
Aave (AAVE) $ 185.64 0.92%
usd1-wlfi
USD1 (USD1) $ 0.999358 0.01%
bitget-token
Bitget Token (BGB) $ 3.61 0.48%