North Korea's BlueNoroff Uses AI Deepfakes for Mac Malware Scam

Edward Zhou
Edward Zhou

CEO & Co-Founder

 
July 17, 2025
3 min read

North Korea’s BlueNoroff Uses AI Deepfakes for Mac Malware

In a sophisticated new campaign, North Korea's BlueNoroff is employing AI-generated video calls to trick executives into installing malware on their Mac systems. This targeted attack specifically aims at cryptocurrency firms, delivering a custom-built malware suite.

Business woman female team leader manager executive having hybrid office business group meeting, remote workers discussing work plans by video digital conference call on laptop. Over shoulder view

Image courtesy of CSO Online

Attack Methodology

BlueNoroff is utilizing deep fakes of company leadership to persuade employees to download fake Zoom extensions, which then install a suite of macOS malware. According to Huntress, the intrusion was reported by a cryptocurrency foundation after an employee installed a suspicious Zoom extension. Initial access to the victim’s system was achieved through a Telegram message that contained a seemingly harmless meeting request.

The victim received a Google Meet invite that redirected them to a fake Zoom site controlled by the attackers. During the meeting, AI-generated deep fakes of their bosses instructed the employee to install a ‘Zoom extension’ to resolve a microphone issue.

Randolph Barr, CISO at Cequence, noted, “This attack is a powerful example of how threat actors are evolving.” The use of AI-generated deepfakes combined with personalized social engineering represents a significant shift in cyberattack sophistication.

Malware Characteristics

The malware delivered includes a variety of macOS threats, such as info-stealers, keyloggers, and backdoors. Key features of the malware include:

  • Advanced Tradecraft: Techniques like clipboard monitoring and sleep-aware command execution were observed.
  • Distinct Binaries: Huntress identified eight malicious binaries, including:
    • Telegram 2: A Nim-based binary acting as the primary backdoor.
    • Root Troy V4: A fully-featured Go backdoor for executing payloads.
    • InjectWithDyId: A C++ loader capable of process injection, utilizing AES-CFB for payload decryption.
    • XScreen: A keylogger for monitoring keystrokes and clipboard data.
    • CryptoBot: A stealer targeting cryptocurrency data.

Each implant was cleverly disguised to avoid detection and was signed to appear legitimate.

Defense Recommendations

To mitigate the risk posed by such sophisticated threats, Barr recommends employing robust technical solutions. Utilizing Mobile Device Management (MDM) platforms can enforce strict access controls, while Endpoint Detection and Response (EDR) solutions provide real-time visibility into endpoint activities.

“Layered defenses that combine user training with strong endpoint controls, policy enforcement, and behavioral analytics are not optional — they’re essential,” Barr emphasized.

Ongoing Threat Landscape

BlueNoroff is a subgroup of the Lazarus Group, known for targeting cryptocurrencies since at least 2017. The group's history includes orchestrating financial crimes and leveraging social engineering tactics to gain access to sensitive information.

In particular, the campaign mirrors previous tactics used in the "Contagious Interviews" scheme, where attackers posed as recruiters to deliver malware-laden files as part of fake job assessments. This evolution in attack methods continues to pose significant risks to organizations, especially those in high-stakes financial sectors.

For further insights, refer to the assessments by DTEX on North Korea's cyber structure and the evolution of their threat groups.

Edward Zhou
Edward Zhou

CEO & Co-Founder

 

CEO & Co-Founder of Gopher Security, leading the development of Post-Quantum cybersecurity technologies and solutions.

Related News

2026 Cybersecurity Trends: Dominance of Vulnerability Exploits
vulnerability exploits

2026 Cybersecurity Trends: Dominance of Vulnerability Exploits

Vulnerability exploits now account for 40% of cyber intrusions, surpassing phishing. Learn how shrinking patch windows and edge device targets are changing security.

By Brandon Woo April 6, 2026 3 min read
common.read_full_article
Surge in Vulnerability Exploits: Cyber Intrusions Trends 2026
cybersecurity trends 2026

Surge in Vulnerability Exploits: Cyber Intrusions Trends 2026

Vulnerability exploits now drive 40% of cyberattacks as hackers weaponize flaws within hours. Learn why traditional patching is failing and how to adapt. Read more.

By Divyansh Ingle March 30, 2026 3 min read
common.read_full_article
Surge in Vulnerability Exploits Dominates 2026 Cyber Intrusions
Vulnerability Exploitation

Surge in Vulnerability Exploits Dominates 2026 Cyber Intrusions

Hackers are weaponizing zero-days within hours of disclosure, leaving traditional patch cycles in the dust. Learn how to bridge the security gap with MFA and Zero-Trust.

By Alan V Gutnov March 23, 2026 4 min read
common.read_full_article
Vulnerability Exploits Dominate Cyber Intrusions in 2026 Trends
vulnerability exploits

Vulnerability Exploits Dominate Cyber Intrusions in 2026 Trends

Exploits are the leading cause of cyber intrusions, outpacing phishing. Discover the latest trends and essential strategies to protect your organization. Read now!

By Brandon Woo March 16, 2026 3 min read
common.read_full_article