New Deepfake Phishing Attack Targets Bitcoin Users via Zoom and Teams
A phishing campaign utilizing deepfake technology is currently targeting Bitcoin users through fraudulent Zoom and Microsoft Teams calls.
A phishing campaign utilizing deepfake technology is currently targeting Bitcoin users through fraudulent Zoom and Microsoft Teams calls.
Attackers employ video conferencing, Telegram, and AI-generated identities to steal Bitcoin and compromise victims' digital security.
The attack begins on Telegram, where victims receive messages or call requests appearing to be from trusted figures in the Bitcoin community. The attacker then initiates a Zoom or Microsoft Teams call using a link shared via Telegram.
During the video call, the attacker uses AI deepfake technology to impersonate a familiar face, such as a colleague or a known Bitcoin personality. The video is designed to appear authentic, reducing suspicion when combined with a context-aware conversation.
Once trust is established, the attacker claims to have audio issues and instructs the victim to install a supposed "plugin," "audio fix," or "update," which is actually malware granting the attacker full remote access.
A phishing campaign utilizing deepfake technology is currently targeting Bitcoin users through fraudulent Zoom and Microsoft Teams calls.
After the malware is installed, the attacker can:
Steal Bitcoin from hot wallets on the machine. Hijack Telegram accounts to extend the attack to new targets. Capture passwords, browser sessions, and authentication tokens for other services.
Compromised accounts are used to contact more victims, making the campaign particularly dangerous in close-knit Bitcoin and crypto communities.
Security professionals advise Bitcoin users and crypto enthusiasts to take the following precautions:
Avoid accepting Zoom or Microsoft Teams calls initiated via Telegram links . Treat all Telegram messages as untrusted, even if they appear to come from known contacts. Never install plugins, updates, or "fixes" suggested during a live call. Use more controlled platforms like Signal, Jitsi, or Google Meet for sensitive discussions. Employ reputable endpoint protection and conduct regular malware scans.
Attackers operate professionally, merging deepfake video, social engineering, and malware to exploit trust and urgency. The Bitcoin community emphasizes the importance of verifying identities out-of-band and questioning all requests before clicking, installing, or approving access.
Based on reporting by GBHackers.
