Detect Deepfakesby Resemble AI
Deepfake case study · Multi-modal

This AI Is Already Fooling People on Video Calls Into

North Korea-linked hackers utilized deepfake video and audio on video conferencing platforms to impersonate trusted contacts and distribute malware

Reported date
Oct 2, 2026
Target
Unnamed victims of North Korea-linked hackers

The exact incident date was not established. This entry is dated by its source report.

Updated Oct 3, 2026 · 1 min read

North Korea-linked hackers have leveraged deepfake technology to conduct sophisticated social engineering attacks on video conferencing platforms. By impersonating trusted contacts, these threat actors successfully deceived victims into installing malicious software under the guise of necessary technical updates.

What happened

Security researchers have attributed these intrusions to BlueNoroff, a subsidiary of the Lazarus Group. During these attacks, the threat actors utilized deepfake video and audio to convincingly mimic individuals known to the targets. These calls were conducted over platforms such as Zoom or Teams, where the attackers used the fabricated identities to build rapport and trust. Once the victims were engaged, the hackers convinced them to install malware, which was presented to the targets as an audio fix. This incident highlights the growing risk of synthetic media in professional environments, where traditional visual and auditory verification methods are no longer sufficient to confirm the identity of a caller. As these technologies evolve, organizations are increasingly forced to implement unconventional security measures, such as asking spontaneous, localized questions to verify the authenticity of job applicants or contacts, as seen in other defensive efforts against similar North Korean-linked campaigns.

Sources