logo

UNC1069 Targets Financial Firms With New Tools and AI-Driven Social Engineering Attacks

ID: c7234c82-3f86-52b8-9ddd-d5a53b2cd342

STIX ID: report--c7234c82-3f86-52b8-9ddd-d5a53b2cd342

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-02-10

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

UNC1069, a North Korean financially motivated threat actor active since 2018, executed a sophisticated campaign against a FinTech/cryptocurrency organization using AI-enabled social engineering (a spoofed Calendly/Zoom meeting and a reported deepfake) and deploying seven malware families—including new tools SILENCELIFT, DEEPBREATH, and CHROMEPUSH—to harvest credentials, browser data, and session tokens; the report outlines ClickFix tactics, detailed TTPs, and multiple IOCs (malicious domains and C2 servers).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.