Deepfake Cyber Attacks: Emerging Threats in South Asia's Digital Landscape
Advanced Persistent Threat (APT) groups are increasingly leveraging deepfake technologies to execute sophisticated cyber attacks in South Asia, posing significant risks to regional security and economic stability.
Executive Takeaway — TL;DR
- Category:
- AI Cyber Attacks
- Severity:
- Medium
- Actor Type:
- APT
- Geography:
- South Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
In recent years, Advanced Persistent Threat (APT) groups have been increasingly leveraging deepfake technologies to execute sophisticated cyber attacks in South Asia. These attacks employ AI-generated media—such as videos, audio, and images—to manipulate individuals and organizations, leading to significant security and economic repercussions.
Deepfake Technology in Cyber Attacks
Deepfake technology utilizes artificial intelligence to create hyper-realistic media that can convincingly mimic real individuals. This capability has been weaponized by cybercriminals to conduct various forms of social engineering, including:
-
Synthetic Identity Operations: Creating fake identities to gain unauthorized access to sensitive information or systems.
-
AI-Generated Phishing Media: Crafting deceptive emails, videos, or audio messages that appear legitimate to deceive recipients into divulging confidential information.
-
Business Email Compromise (BEC) via Deepfake Voice Calls: Impersonating executives or trusted individuals through AI-generated voice calls to authorize fraudulent transactions or disclose sensitive data.
Notable Incidents in South Asia
Several incidents in South Asia highlight the growing threat of deepfake cyber attacks:
-
Kimsuky APT Group's Deepfake Military ID Fraud: In July 2025, the North Korean-linked Kimsuky group employed AI-generated deepfake images of South Korean military ID cards to execute a spear-phishing attack on a defense-related institution. The attackers used generative AI tools to produce realistic ID card images, which were then utilized to impersonate officials and gain unauthorized access to sensitive information. (genians.co.kr)
-
Chollima APT Group's Synthetic Interview Operation: In November 2025, the Chollima APT group, associated with North Korean state-sponsored actors, used real-time AI facial filters during live video interviews to impersonate qualified job candidates. This tactic aimed to infiltrate cryptocurrency and Web3 companies by masquerading as legitimate professionals, thereby facilitating espionage and potential fund acquisition. (socradar.io)
Implications and Risks
The utilization of deepfake technologies by APT groups in South Asia presents several critical challenges:
-
Erosion of Trust: Deepfake attacks can undermine trust in digital communications, making it difficult for individuals and organizations to discern legitimate interactions from fraudulent ones.
-
Financial Losses: Sophisticated deepfake scams have led to significant financial losses. For instance, in 2024, a Hong Kong office of a multinational company lost US$25.6 million due to a deepfake video conference call impersonating its chief financial officer. (globalinitiative.net)
-
National Security Threats: Deepfake technologies can be exploited to spread misinformation, influence public opinion, and disrupt national security, as seen in various incidents across the Asia-Pacific region. (globalinitiative.net)
Mitigation Strategies
To counter the rising threat of deepfake cyber attacks, organizations and individuals should consider the following measures:
-
Enhanced Verification Processes: Implement multi-factor authentication and robust verification protocols to confirm the identity of individuals in digital communications.
-
Employee Training: Conduct regular training sessions to raise awareness about deepfake technologies and their potential misuse, enabling staff to recognize and respond to suspicious activities.
-
Advanced Detection Tools: Invest in AI-driven tools capable of detecting deepfake content, thereby improving the ability to identify and mitigate fraudulent media.
Conclusion
The integration of deepfake technologies into cyber attack strategies by APT groups in South Asia signifies a concerning evolution in the cyber threat landscape. Proactive measures, including technological advancements and comprehensive training, are essential to mitigate the risks associated with these sophisticated attacks.
Highlights:
- AI impersonation scams are sky-rocketing in 2025, security experts warn - here's how to stay safe, Published on Sunday, August 31
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



