Fake Zoom meeting and ClickFix crypto scam illustration

TLDR summary

On February 9, 2026, Mandiant described a crypto-sector intrusion in which attackers used a compromised Telegram account, a spoofed Zoom meeting and a ClickFix prompt to trick a victim into running malicious commands. Microsoft separately documented new ClickFix variants on February 5, 2026, and U.S. agencies later published fresh 2025 fraud-loss data showing how expensive impersonation and AI-enabled scams have become. For exchange users, the lesson is simple: a fake support or meeting flow can be enough to steal browser sessions, email access and wallet context without breaking exchange custody directly.

Key takeaways

  • This attack path relies on social engineering plus user-executed commands, not a classic exchange hot-wallet breach.
  • Mandiant said the crypto-targeted intrusion deployed seven malware families and aimed to harvest credentials, browser data, Telegram data and Apple Notes content.
  • The fake Zoom meeting used a domain hosted on attacker infrastructure, not the real Zoom service.
  • Mandiant reported the victim saw what appeared to be a deepfake video, but that specific AI-video use was not independently verified.
  • Exchange users should treat any unsolicited troubleshooting instruction, remote-access request or urgent fund-move warning as hostile until verified through official channels.

The incident that changed the conversation

Mandiant's February 9, 2026 write-up matters because it connected several threat patterns into one practical crypto attack flow. The victim was approached on Telegram from an executive account that had allegedly already been compromised. After some rapport-building, the victim was sent a Calendly invite that led to a spoofed Zoom meeting hosted on attacker infrastructure. During the call, the victim was pushed into running supposed audio-fix commands. That was the real attack step.

Mandiant said the intrusion targeted a FinTech organization in the crypto sector and attributed the activity to UNC1069, a financially motivated group it has tracked since 2018 with a suspected North Korea nexus. The firm said the actor has been targeting the Web3 industry since at least 2023, including centralized exchanges, software developers, wallet infrastructure and venture-capital-linked individuals.

How the attack flow worked

  1. A trusted contact channel was compromised first, in this case a Telegram account tied to a crypto executive.
  2. The victim was moved into a scheduled meeting flow using a Calendly link that pointed to a spoofed Zoom environment.
  3. The fake meeting created a believable technical problem, reportedly audio failure.
  4. The victim was then told to copy and run troubleshooting commands on macOS or Windows.
  5. Those commands started the infection chain, which Mandiant said led to malware such as WAVESHAPER, HYPERCALL, HIDDENCALL, SILENCELIFT, DEEPBREATH, SUGARLOADER and CHROMEPUSH.
  6. The follow-on goal was data harvesting: keychain credentials, browser data, Telegram content, notes, session material and identity context that could support theft or later impersonation.

Why ClickFix is dangerous for exchange users

ClickFix is effective because it bypasses the mental model many crypto users already have. People expect phishing links and fake wallet popups. They are less prepared for a screen that tells them to fix browser, audio or verification issues by running a command themselves. Microsoft said ClickFix campaigns commonly rely on that manual copy-paste step, which helps them slip past controls that are designed for ordinary downloads or drive-by exploits.

For exchange users, the most exposed assets are often not coins sitting in a cold wallet. They are browser sessions, email inboxes, password-manager vaults, messaging accounts, saved API keys and recovery paths. Once those are compromised, an attacker may not need your seed phrase to cause damage.

What data or access can be exposed?

TargetWhy attackers want itWhat it can lead to
Browser cookies and sessionsThey can bypass a normal login flow.Exchange account takeover or deeper phishing using real account context.
Email accessEmail is often the recovery layer for exchange accounts.Password resets, device approvals and support impersonation.
Telegram and other chat appsCompromised chats can be reused to target more victims.Follow-on scams against coworkers, founders, investors or customers.
Wallet-related files and extension dataAttackers look for credentials, configuration and transaction context.Self-custody theft, malicious approvals or better-targeted social engineering.
Identity documents and notesStolen context makes fake support more convincing.Account-recovery fraud and impersonation attempts.

Current risk context in 2026

The February intrusion was not an isolated curiosity. On February 5, 2026, Microsoft documented a new ClickFix variant called CrashFix that deliberately broke the browser experience and then used fake repair prompts to get victims to execute malicious commands. The broader scam backdrop is also getting worse. On June 15, 2026, the FTC said people reported losing $3.5 billion to imposter scams in 2025, with imposter scams representing nearly one in three fraud reports. On April 6, 2026, the FBI said Americans who submitted cryptocurrency-related complaints reported more than $11 billion in losses and that AI-related complaints alone cost nearly $893 million.

Those figures do not prove every crypto user faces the same threat level, but they do show that impersonation and AI-assisted deception are no longer edge cases. They are mainstream fraud infrastructure.

User checklist before, during and after a suspicious call

MomentRed flagSafer action
Before joiningThe meeting link came through Telegram, WhatsApp or a forwarded calendar invite.Verify the person and domain independently. Type the company URL yourself or confirm through a second channel.
During the callYou are told to copy a command, install software or enable remote access.Stop immediately. Legitimate exchange support should not need your terminal or device control.
During the callYou are told to move funds to a new wallet, vault or safe address.End the call. Coinbase and other major exchanges explicitly warn that support should never ask you to move funds for safety.
Right afterYou clicked or ran something and now the device behaves oddly.Disconnect the device, switch to a clean device, lock accounts and rotate credentials.
LaterContacts receive strange messages from your account.Assume your chat and email identity may be part of the attack chain and warn people quickly.

Response steps if you already ran the command

  1. Disconnect the affected device from the internet.
  2. From a known-clean device, change your email password first, then exchange passwords and any linked authenticator or backup methods.
  3. Revoke active sessions and API keys where your exchange or wallet provider allows it.
  4. Turn on or rebind withdrawal allow-listing and use the strongest available 2FA, ideally a hardware key.
  5. Check recent withdrawal-address changes, device confirmations, login history and support interactions.
  6. Contact the exchange through its official help center, not a phone number or link supplied in the suspicious contact.
  7. Warn close contacts that your messaging account may have been used for impersonation.

Risk notes users should not miss

  • A realistic meeting invite is now part of the attack surface for crypto, not just email and cloned websites.
  • The most convincing scammer may know your role, holdings range, coworker names or recent business context.
  • Deepfake claims are easy to overstate. In this case, Mandiant reported what the victim saw but did not independently verify the video manipulation.
  • Even if an exchange's custody stack is sound, user-device compromise can still lead to account takeover, social engineering or wallet theft.

CryptoGuide take

The hype angle here is AI, but the trust-first lesson is older and more important: the real failure point is still human verification. Deepfakes and polished fake meetings matter because they make bad instructions feel routine. Users should not respond by assuming every platform is unsafe. The better response is narrower and more useful: never let a live call override your security rules. If a platform, founder or support agent wants you to run a command or move funds urgently, the burden of proof is on them, and you should verify through an official path you opened yourself.

Sources and further reading

FAQ

What is a ClickFix scam in crypto?

A ClickFix scam tricks the victim into copying and running a command on their own device under the pretext of fixing audio, browser or security problems. In crypto cases, that can expose exchange logins, browser sessions, wallet data and messaging accounts.

Did Mandiant confirm deepfakes were used in the crypto fake Zoom case?

No. Mandiant said the victim reported seeing what appeared to be an AI-generated deepfake video during the fake Zoom meeting, but Mandiant did not independently verify that specific deepfake use.

What should exchange users do if they ran a suspicious troubleshooting command?

Disconnect the device from the internet, move to a known-clean device, change exchange and email credentials, revoke sessions, rotate two-factor methods where needed, lock accounts if available, and contact the relevant exchange through official support channels.

Conclusion

Crypto scams are moving closer to normal work and support behavior. A fake Zoom room, a believable contact and a copy-paste fix can be enough to open the door. That does not mean users need to panic or stop using exchanges. It means trust decisions now have to include the meeting link, the support path and the device in front of you, not only the exchange brand on the login page.

Related articles