North Korean hackers deepfake execs in Zoom call to spread Mac malware

The North Korean hacker collective BlueNoroff is deceiving employees into installing malicious software on their macOS laptops by deepfaking company bosses during Zoom calls.

BlueNoroff, also known as Sapphire Sleet or TA444, is a North Korean advanced persistent threat (APT) gang that uses malware for Mac and Windows to steal cryptocurrency.

When Huntress researchers were called to look into a possible penetration on a partner’s network on June 11, 2025, they discovered a new BlueNoroff attack. The main objective, as in earlier attacks, was probably bitcoin theft, which is consistent with other recent findings about the threat actors from Microsoft, SentinelLabs, Jamf, and Kaspersky.

The attackers used Telegram to contact the victim, a tech company employee, pretending to be outside experts who wanted read more about North Korean hackers deepfake execs in Zoom call to spread Mac malware.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *