Hackers Use ClickFix Scam to Target Crypto Executive via Fake Zoom Meetings

Google-owned Mandiant Cybersecurity Consulting has published a detailed report about the new ClickFix scam.

Advertisement
Written by Dhruv Raghav, Edited by David Delima | Updated: 11 February 2026 18:26 IST
Highlights
  • Hackers use AI-generated fake videos to dupe victims
  • ClickFix victims are initially contacted through Telegram
  • Bad actors ran cryptocurrency theft campaigns

Hackers can use compromised Telegram accounts to send Zoom links to victims

Photo Credit: Unsplash/NordWood Themes

A North Korea-based hacker group is specifically targeting executives of cryptocurrency and decentralised finance companies to run crypto theft campaigns, according to a Google-owned cybersecurity consulting firm. The hackers use compromised Telegram accounts to infect targeted systems and fake Zoom meeting links to dupe victims. After gaining access to their victims' credentials and accounts, the hackers change passwords to block user access. When a user joins the fake Zoom meeting, they are shown AI-generated videos to gain their victims' trust.

North Korean Hackers Use AI-Generated Videos to Dupe Crypto Executives via ClickFix

The Record reports that a group of North Korean hackers targeted a cryptocurrency company official via a fake Zoom meeting, various malware, and social engineering manoeuvres. On Tuesday, Google-owned Mandiant Cybersecurity Consulting published a report detailing the modus operandi of UNC1069 hackers who exploit the ClickFix scam to specifically target entities in the cryptocurrency and decentralised finance industry.

Advertisement

Mandiant explained that the North Korean bad actor employed a social engineering scheme, where the victim was contacted via a “compromised Telegram account”. A fake Zoom meeting link is then sent to the user, which contains the ClickFix infection vector. In the Zoom meeting, the victims are shown AI-generated deep fake videos of people to make the Zoom meeting appear genuine.

As part of the ClickFix scam, the UNC1069 hacker deploys seven “unique malware families”, which Mandiant calls SILENCELIFT, DEEPBREATH, and CHROMEPUSH, which are a set of tools specifically designed to access the data of the victim. Hackers also use multiple infected files, dubbed WAVESHAPER and HYPERCALL, to gain backdoor access to the victim's system. User details such as credentials, browser data, and session tokens are stolen by bad actors for cryptocurrency and other types of financial scams.

The cybersecurity consulting firm also highlighted that the UNC1069 threat actor has expanded into injecting targeted systems with new malware families, along with SUGARLOADER, moving from AI-enabled attacks. The UNC1069 hacker is known for using Gemini to “develop tooling, conduct operational research, and assist” while researching about the victim, according to a report by Google Threat Intelligence Group (GITG).

Similar to the latest reported incident, in May 2025, Ryan Kim, a Founding Partner at Hashed, a blockchain firm, shared that he was recently targeted by a group of hackers via Telegram. A meeting was set up by Kim through Calendly. Later, a fake Zoom meeting link was sent to him, prompting as a Zoom SDK update, which then turned out to be malware. When Kim joined the meeting, he saw various personalities from the crypto industry.

Advertisement

He highlighted that the audio did not work on Zoom, and other attendees appeared to be deepfakes. The Hashed executive was again prompted to install the SDK update, which he did, unknowingly infecting his system in the process. Using the Telegram Desktop session, the attacker was able to restrict access to the instant messaging app from other devices, while also changing his password and recovery mail. The bad actor was even able to bypass 2FA on Telegram.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: ClickFix Scam, Zoom, Cryptocurrency, Google
Advertisement
Popular Mobile Brands
  1. Samsung Galaxy Buds 3 Pro, Buds 4 Pro Get FDA-Cleared Hearing Aid
  2. This Flagship Oppo Tablet Could Launch in India Soon
  3. iQOO Neo 11 Ultra Will Launch With This 2K Resolution Display
  4. Spider-Man: Brand New Day Has Lifted Sales of Spider-Man 2 on PS5 and PC
  5. iQOO Neo 11 Ultra Full Specifications List Revealed via China Telecom Site
  6. Vivo X500 Series Design, Display and Camera Details Leak Ahead of Launch
  7. Realme 16x 5G Debuts in India With MediaTek Dimensity 6300 SoC
  8. Redmi Note 17 Pro Max Could Launch With This Snapdragon Chipset
  1. Bitcoin Slips Below $64,000 as Investors Await US Inflation Data
  2. Total Solar Eclipse Today: How to Watch Live Online, Timings, Safety Tips, and More
  3. iQOO Neo 11 Ultra Display and Design Details Confirmed Ahead of August 18 Launch
  4. Spotify Will Label AI-Generated Artist Profiles With New AI Persona Badge
  5. Sony Announces Limited-Edition Marvel's Wolverine PS5 Bundle and Accessories in Striking See-Through Designs
  6. Redmi Note 17 Goes on Sale in India With Snapdragon 4 Gen 4 Chip, 8,000mAh Battery: Price, Specifications
  7. Realme 16x 5G Launched in India With MediaTek Dimensity 6300 SoC, 7,000mAh Battery: Price, Specifications
  8. Oppo Pad 5 Pro India Launch Tipped as Tablet Appears on BIS Certification Website
  9. Samsung Galaxy Z Fold 8 Durability Test Shows Strong Build, Fragile Inner Screen
  10. Samsung Galaxy Buds Hearing Aid Feature Gets FDA Clearance, to Roll Out in Q4 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.