North Korean Hackers Use Deepfakes in Zoom Calls to Infect macOS Devices with Malware

Listen to this Post

Featured Image

Digital Deception at a New Level

In a disturbing evolution of cyber warfare, North Korea’s BlueNoroff hacking group has begun using deepfake technology to impersonate company executives during fake Zoom meetings. This sophisticated method is designed to manipulate unsuspecting employees into installing custom macOS malware, primarily aimed at cryptocurrency theft. The attack, recently uncovered by Huntress on June 11, 2025, illustrates how threat actors are combining artificial intelligence, social engineering, and platform-specific malware to infiltrate businesses under the guise of routine virtual meetings. With macOS gaining ground in the enterprise world, this incident is a stark reminder that no operating system is immune from highly targeted and evolving cyber threats.

A Detailed Breakdown of the Cyber Attack Strategy

The attack started with a simple yet convincing outreach on Telegram. An employee at a tech firm was contacted by someone posing as an external business associate and invited to what appeared to be a Google Meet session. However, the link redirected them to a fake Zoom domain. Once in the call, the employee found themselves in a convincing video conference that included deepfake videos of their company’s executives, along with other professional-looking participants.

This elaborate Zoom meeting was more than a hoax — it was a setup. When the victim experienced microphone issues during the call, the deepfaked executive recommended downloading a Zoom extension to fix the problem. The download was actually a malicious AppleScript file named zoom_sdk_support.scpt. Upon execution, this file opened a legitimate Zoom SDK webpage, hid thousands of blank lines to mask its behavior, then executed a command to retrieve a malicious payload from a disguised domain.

Though Huntress arrived after the payload was removed from the command-and-control server, researchers managed to analyze a version uploaded to VirusTotal. The script disabled bash logging, installed Rosetta 2 silently if needed, and downloaded malware to the /tmp directory under the name icloud_helper.

This wasn’t a simple one-off attack. Analysts discovered eight distinct malware binaries, which included:

Telegram 2: A persistence implant disguised as a Telegram updater, signed with an authentic developer certificate to avoid detection.
Root Troy V4: A powerful Go-based backdoor capable of executing remote commands, downloading more malware, and maintaining system control even during idle states.
InjectWithDyld: A decryption loader that injects implants directly into memory, using macOS-specific methods and antiforensics to erase its trail.
XScreen: A surveillance tool that logs keystrokes, records screens, and monitors clipboard activity.
CryptoBot: A cryptocurrency-targeting malware written in Go, designed to steal from over 20 wallet platforms and cache data for exfiltration.

These malware tools reflect a well-coordinated and multi-stage attack infrastructure, showing that BlueNoroff has evolved far beyond basic scams. By employing deepfakes and Zoom-themed deception, they’re weaponizing trust, exploiting the virtual work environment, and targeting the growing macOS enterprise landscape.

Huntress emphasized a growing concern: many Mac users still believe their devices are safer from malware threats. But as cybercriminals like BlueNoroff adapt, Mac users are becoming increasingly attractive targets. With the rising adoption of macOS in corporate environments, the need for heightened vigilance and proactive defense strategies has never been more critical.

What Undercode Say:

The Deepfake Cyber Threat Landscape

The BlueNoroff attack signals a seismic shift in how cybercriminals conduct social engineering. Deepfakes — once a curiosity — are now being weaponized in real-world cyberattacks. By mimicking high-ranking executives, threat actors are gaining unprecedented psychological leverage over victims, tricking them into bypassing traditional security barriers out of perceived trust.

Multi-Layered Deception Using Familiar Tools

What makes this attack particularly dangerous is its use of recognizable platforms like Zoom and Calendly, which don’t usually raise red flags. The attackers carefully crafted every interaction to feel authentic, even embedding deepfaked video streams to replicate real-time engagement. This kind of attention to psychological realism drastically lowers an employee’s guard.

macOS No Longer Off-Limits

Historically, macOS has enjoyed a reputation as a secure platform, partly due to its smaller user base in enterprise environments. But that’s changing rapidly. As macOS gains popularity in tech startups and design-heavy companies, cybercriminals are responding with platform-specific malware. BlueNoroff’s approach — particularly the use of Rosetta 2 to target both Intel and Apple Silicon chips — shows just how prepared these threat actors are.

Advanced Payload Deployment Tactics

The use of AppleScript files with massive padding, the silent installation of Rosetta, and the file placement in hidden directories all point to high levels of operational security on the attacker’s side. These are not random scripts — they are carefully engineered payloads designed for stealth and persistence.

The Weaponization of Trust in Remote Work

Remote work culture has normalized video calls, links from strangers, and digital calendar invites. Attackers are taking advantage of this shift. Employees are less likely to question a Zoom invite, especially if it includes familiar faces and executive figures. Deepfakes used in real-time communication make it nearly impossible for the average employee to distinguish fact from fiction.

Threat to Crypto and Beyond

Although this campaign’s main goal appears to be stealing cryptocurrency, the tools used are adaptable for espionage, intellectual property theft, or broader financial crimes. Tools like CryptoBot, XScreen, and Root Troy V4 give attackers full control over the compromised system, making this a significant risk beyond just crypto wallets.

What Enterprises Must Do

Security awareness training must evolve to include AI-driven threats like deepfakes. IT teams should also implement behavioral analytics, endpoint detection systems, and strict application controls to identify and contain these threats early. Relying solely on traditional antivirus tools is no longer sufficient in a world where malware is signed with legitimate developer certificates.

The Erosion of Visual Verification

This attack also exposes a growing problem: the unreliability of video as a trust signal. We are conditioned to believe what we see — a vulnerability now exploited by cybercriminals using AI. The future of security will likely require alternate forms of authentication that do not rely on visual presence.

The Bottom Line

BlueNoroff has proven it can combine AI deepfakes, cross-platform malware, and social engineering to infiltrate even security-aware organizations. This kind of threat needs immediate attention, especially as AI tools become easier to access and deploy. The arms race between cybercriminals and defenders has entered a new phase — one where reality itself can no longer be trusted.

🔍 Fact Checker Results:

✅ Verified: BlueNoroff used deepfakes in Zoom calls for social engineering
✅ Verified: Malware targeted macOS devices, including Apple Silicon Macs
✅ Verified: Tools used included CryptoBot, Root Troy, XScreen, and others

📊 Prediction:

🔮 Expect an increase in deepfake-driven cyberattacks across corporate platforms
🔒 Mac-focused malware campaigns will surge, especially targeting finance and tech sectors
🧠 Security awareness training will need to shift toward AI threat recognition and response

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram