Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse

Incident 1117: North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Description: An alleged phishing scheme involving actors linked to North Korea used purported AI-generated deepfake videos of company executives to deceive a Web3 employee during a fake Zoom call. The target was reportedly tricked into installing macOS malware disguised as a "Zoom extension," leading to the deployment of spyware, a keylogger, and a crypto wallet stealer. The attackers reportedly used Telegram and spoofed Zoom domains to orchestrate the breach.
Editor Notes: See also Incident 644: Alleged State-Sponsored Hackers Escalate Purported Phishing Attacks Using Artificial Intelligence.

Tools

New ReportNew ReportNew ResponseNew ResponseDiscoverDiscoverView HistoryView History

Entities

View all entities
Alleged: Unknown voice cloning technology developer and Unknown deepfake technology developer developed an AI system deployed by North Korea , Lazarus Group and BlueNoroff, which harmed Zoom , Web3 , Unnamed Web3 employee , macOS users and Cryptocurrency infrastructure.
Alleged implicated AI systems: Zoom , Unknown voice cloning technology , Unknown deepfake technology , Telegram , macOS and Cryptocurrency wallets

Incident Stats

Incident ID
1117
Report Count
1
Incident Date
2025-06-22
Editors
Daniel Atherton

Incident Reports

Reports Timeline

+1
Tricked on Zoom: Deepfake Scam Leads to macOS Breach
Tricked on Zoom: Deepfake Scam Leads to macOS Breach

Tricked on Zoom: Deepfake Scam Leads to macOS Breach

the420.in

Tricked on Zoom: Deepfake Scam Leads to macOS Breach
the420.in · 2025

A new cyber attack campaign by North Korea-linked group BlueNoroff has come to light, targeting a Web3 industry employee through deepfake Zoom calls and macOS malware. Security researchers say the incident reflects growing sophistication in…

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?

Similar Incidents

Selected by our editors

Alleged State-Sponsored Hackers Escalate Purported Phishing Attacks Using Artificial Intelligence

Feb 2024 · 6 reports
By textual similarity

Did our AI mess up? Flag the unrelated incidents

Hackers Break Apple Face ID

Hackers Break Apple Face ID

Sep 2017 · 24 reports
Reported AI-Cloned Voice Used to Deceive Hong Kong Bank Manager in Purported $35 Million Fraud Scheme

Reported AI-Cloned Voice Used to Deceive Hong Kong Bank Manager in Purported $35 Million Fraud Scheme

Jan 2020 · 6 reports
Game AI System Produces Imbalanced Game

Game AI System Produces Imbalanced Game

Jun 2016 · 11 reports
Previous Incident

Similar Incidents

Selected by our editors

Alleged State-Sponsored Hackers Escalate Purported Phishing Attacks Using Artificial Intelligence

Feb 2024 · 6 reports
By textual similarity

Did our AI mess up? Flag the unrelated incidents

Hackers Break Apple Face ID

Hackers Break Apple Face ID

Sep 2017 · 24 reports
Reported AI-Cloned Voice Used to Deceive Hong Kong Bank Manager in Purported $35 Million Fraud Scheme

Reported AI-Cloned Voice Used to Deceive Hong Kong Bank Manager in Purported $35 Million Fraud Scheme

Jan 2020 · 6 reports
Game AI System Produces Imbalanced Game

Game AI System Produces Imbalanced Game

Jun 2016 · 11 reports

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 69ff178