Hacktivist Deepfake Cyber Attacks in Southeast Asia: A Rising Threat
Hacktivist groups in Southeast Asia are increasingly leveraging deepfake technologies for cyber attacks, including social engineering, synthetic identity operations, AI-generated phishing media, and BEC fraud via deepfake voice calls.
Executive Takeaway — TL;DR
- Category:
- AI Cyber Attacks
- Severity:
- Medium
- Actor Type:
- Hacktivist
- Geography:
- Southeast Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
In recent years, Southeast Asia has witnessed a surge in cyber attacks orchestrated by hacktivist groups employing deepfake technologies. These attacks encompass a range of tactics, including social engineering, synthetic identity operations, AI-generated phishing media, and Business Email Compromise (BEC) fraud via deepfake voice calls. This briefing examines these emerging threats, highlighting specific incidents and the tools utilized by these actors.
Deepfake Social Engineering and Synthetic Identity Operations
Hacktivist groups have increasingly adopted deepfake technologies to enhance their social engineering tactics. By creating realistic audio and video content, they impersonate trusted individuals to manipulate targets into divulging sensitive information or performing unauthorized actions.
For instance, in late 2023, deepfake videos of Singapore’s Prime Minister Lee Hsien Loong and Deputy Prime Minister Lawrence Wong were circulated, promoting fraudulent cryptocurrency investments. These AI-generated clips exploited the likenesses of public figures to lend credibility to the scams, deceiving viewers who trusted the source. (ozforensics.com)
Similarly, in Hong Kong, a multinational firm's local branch was defrauded of HK$200 million (US$25.6 million) after staff were tricked by a deepfake video conference. Scammers created realistic video avatars of the company’s CFO and other executives, instructing employees to transfer funds urgently. The employees complied, believing they were following legitimate directives. (ozforensics.com)
AI-Generated Phishing Media
The integration of AI into phishing schemes has led to more sophisticated and convincing attacks. Hacktivist groups utilize AI to generate personalized phishing emails, voice calls, and video messages that closely mimic legitimate communications.
A 2026 report from Kaseya highlighted that 83% of phishing emails now incorporate AI-generated content, with 40% of BEC attacks utilizing generative AI. These emails boast a 54% click rate due to improved grammar, personalization, and timely content, compared to just 12% for traditional phishing messages. (itpro.com)
BEC Fraud via Deepfake Voice Calls
Deepfake voice technology has been weaponized to execute BEC fraud schemes. Hacktivist groups clone the voices of executives or trusted contacts to deceive employees into authorizing fraudulent transactions.
In Malaysia, scammers used AI-generated voice cloning to impersonate family members, convincing victims to transfer money urgently. The deepfake voices sounded remarkably similar to the victims' relatives, making detection challenging. (malaymail.com)
Tools and Platforms Utilized
Hacktivist groups employ various tools and platforms to facilitate these deepfake cyber attacks:
-
Deepfake Software: Tools designed for fraud are widely sold on platforms like Telegram, enabling the creation of realistic synthetic media. (thedailystar.net)
-
AI-Generated Phishing Tools: AI models are used to craft convincing phishing emails and messages, enhancing the effectiveness of social engineering attacks. (techdemocracy.com)
Conclusion
The use of deepfake technologies by hacktivist groups in Southeast Asia represents a significant escalation in cyber threats. These actors are leveraging advanced AI tools to conduct sophisticated social engineering, synthetic identity operations, and BEC fraud schemes. Organizations in the region must enhance their cybersecurity measures, focusing on AI-driven threats, to mitigate the risks associated with these emerging attack vectors.
Recommendations
-
Employee Training: Regularly educate staff on the risks of deepfake and AI-driven attacks, emphasizing the importance of verifying communications through multiple channels.
-
Advanced Detection Tools: Implement AI-based detection systems capable of identifying deepfake content and anomalous communication patterns.
-
Incident Response Planning: Develop and regularly update incident response plans to address potential deepfake-related security breaches.
By proactively addressing these threats, organizations can bolster their defenses against the evolving landscape of cyber attacks in Southeast Asia.
Highlights:
- 'By replacing a legitimate update with a malicious one, they turned the product's update flow into a malware distribution channel': Experts find flaw in TrueConf video conferencing tool used by governments, military, Published on Thursday, April 02
- Deepfake worries hit a new high as one in four Americans say they have received a deepfake voice call in the past 12 months - experts blame 'the weaponization of AI', Published on Saturday, March 14
- 'AI-generated phishing became the baseline' for hackers last year - Kaseya warns it's going to get worse in 2026, Published on Thursday, March 19
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

AI-Driven Cyber Attacks Surge: 89% Increase in Machine-Assisted Threats Reported

Emerging 'PromptFlux' Variant Leverages Real-Time LLM Code Injection for Stealthy Persistence

