Key Takeaways:
- Crypto insiders are being targeted by deepfake video calls that deliver macOS malware
- BTC Prague co-founder Martin Kuchař says his stolen Telegram account was used to spread the attack
- The campaign matches tactics tied to North Korea–linked BlueNoroff hackers
A crypto scam wave with a highly-targeted level is exploiting deepfake video, relationship contacts and popular work tools. BTC Prague co-founder, Martin Kuchař disclosed that attackers controlled his Telegram account to lure others into Zoom and Teams video call with malware.
Read More: $50M Vanishes in Seconds: Copy-Paste Wallet Error Triggers One of Crypto’s Costliest Address Scams

Table of Contents
- Deepfake Video Calls Used as the Entry Point
- North Korea–Linked Malware Chain Targets Mac Users
- How the Mac Infection Works
- Crypto Theft Campaigns Grow More Sophisticated
Deepfake Video Calls Used as the Entry Point
Kuchař warned that the attacks often start with messages from trusted contacts on Telegram or other platforms. The victims receive an invitation to discuss the matter or also have a quick sync in a Zoom or Microsoft Teams call.
After getting the call, the attackers impersonate the trusted person through AI-generated deepfake video. They state that there is an audio problem and request the victim to install a given plug in or file so as to resolve the issue. That file gives attackers full access to the system.
According to Kuchař, this method led to the theft of Bitcoin, takeover of Telegram accounts, and further spread of the scam through hijacked identities. He urged users to treat all Telegram messages as untrusted and to avoid unverified Zoom or Teams calls.
Read More: Hackers Hijack Binance Co-CEO Yi He’s WeChat to Push Meme Coin Scam, Triggering Market Frenzy

North Korea–Linked Malware Chain Targets Mac Users
Technical details shared by Kuchař align with research from cybersecurity firm Huntress, which traced similar attacks to BlueNoroff, a hacking group linked to North Korea’s Lazarus Group.
How the Mac Infection Works
The attack starts with a spoofed Zoom domain with a faked meeting link. When victims are making the call, they are advised to download a file named Zoom support script. Actually, the file is infected by AppleScript, which starts a multi-stage attack.
The malware toolkit will consist of:
- Telegram 2, a fake updater that maintains persistence
- Root Troy V4, a remote-access backdoor
- InjectWithDyld, a stealth loader for encrypted payloads
- XScreen, a surveillance tool that logs keystrokes and screen activity
- CryptoBot, an infostealer targeting more than 20 crypto wallets
Researchers indicate that the malware will leverage valid developer signatures and place Rosetta on Apple Silicon devices in order to evade identification. This renders the attack less detectable, particularly to the Mac users who have a false sense of security that their respective systems are less vulnerable.
Crypto Theft Campaigns Grow More Sophisticated
Huntress researchers point out that Mac is an excellent target because an increasing number of crypto groups deploy Macs to the enterprise. Deepfake video injects strongly in the credibility equation, combining real-time images with the known platform.
Basic security habits revealed by Kuchař assisted in curtailing his losses. He emphasized the use of two-factor authentication, password solution, and hardware wallets. He also recommended more secure communication tools, such as Signal or Jitsi, and better browsers over more secure calls, such as Google Meet due to greater sandboxing.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Related Articles
U.S. Military Confirms Bitcoin Node Operations as Multiple Nations Adopt Crypto for Statecraft
Gate News message, April 26 — Admiral Samuel Paparo, Jr., who leads U.S. forces across the Indo-Pacific, told a Senate panel that Bitcoin matters to national security. The Pentagon is running its own Bitcoin node and conducting operational tests to secure and protect networks using the Bitcoin
GateNews1h ago
Bitcoin Funding Rate Turns Negative at -0.0031%, Major CEXs Show Mixed Rates
Gate News message, April 26 — According to Coinglass, Bitcoin's 8-hour average funding rate across the network is currently -0.0031%, indicating a bearish sentiment among traders.
Among major centralized exchanges, funding rates vary: a leading CEX shows 0.0002%, another major CEX at -0.0004%, a th
GateNews4h ago
Whale Deposits 300 BTC Worth $23.4M to CEX After 2-Year Dormancy
Gate News message, a whale has deposited 300 BTC (valued at $23.4 million) into a centralized exchange after remaining inactive for 2 years. These 300 BTC were originally withdrawn from CEX 3 years ago when BTC was priced at $19,329. The whale is currently holding an unrealized profit of $17.6 milli
GateNews6h ago
Metaplanet Issues ¥8B Bonds To Expand Bitcoin Holdings
Metaplanet raises ¥8B through zero-coupon bonds to fund Bitcoin purchases without immediate interest burden.
Firm grows BTC reserves to over 40K coins, targeting 100K by year-end despite valuation-driven losses.
Strategy relies on debt financing as stock declines, reflecting risk amid
CryptoFrontNews6h ago
CryptoQuant Analyst: Bitcoin Must Hold Above $83K to Confirm Market Recovery
Gate News message, April 26 — According to CryptoQuant analyst Axel Adler, short-term holder (STH) selling pressure has notably eased following spring market stress relief, and Bitcoin's market recovery remains underway. Current BTC price has approached the short-term holder cost basis.
Adler
GateNews7h ago
El Salvador Adds 8 BTC Over Past Week, Total Holdings Reach 7,633.37 Bitcoin
Gate News message, April 26 — El Salvador added 8 Bitcoin over the past 7 days, bringing its total holdings to 7,633.37 BTC worth approximately $624 million.
Over the past 30 days, the country has accumulated 31 Bitcoin, continuing its strategy of building its national Bitcoin
GateNews8h ago