UNC1069 Targets Financial Firms With New Tools and AI-Driven Social Engineering Attacks
ID: c7234c82-3f86-52b8-9ddd-d5a53b2cd342
STIX ID: report--c7234c82-3f86-52b8-9ddd-d5a53b2cd342
Feed Name: GBHackers
UNC1069, a North Korean financially motivated threat actor active since 2018, executed a sophisticated campaign against a FinTech/cryptocurrency organization using AI-enabled social engineering (a spoofed Calendly/Zoom meeting and a reported deepfake) and deploying seven malware families—including new tools SILENCELIFT, DEEPBREATH, and CHROMEPUSH—to harvest credentials, browser data, and session tokens; the report outlines ClickFix tactics, detailed TTPs, and multiple IOCs (malicious domains and C2 servers).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
