logo

North Korea-Linked UNC1069 Hacks Crypto Pros via Fake Meetings

ID: d26e8657-ba30-5ccf-97cd-261634655f3a

STIX ID: report--d26e8657-ba30-5ccf-97cd-261634655f3a

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-20

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

UNC1069, a North Korea-linked threat actor, is conducting highly targeted campaigns against cryptocurrency and Web3 professionals by hijacking accounts and luring victims into fake Zoom/Google Meet/Microsoft Teams sessions that coerce users to paste terminal/PowerShell commands. The campaign uses multi-stage, cross-platform malware (Windows VBS/Cabbage RAT variants, macOS Mach-O downloaders leading to NukeSped RAT, and ELF RATs on Linux), browser-based covert surveillance on fake meeting pages, and supply-chain techniques (e.g., compromised npm packages) to achieve long-term access and asset theft; defenders are advised to verify counterparties out-of-band, block risky scripting behaviors, monitor related infrastructure, and enforce least-privilege controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.