logo

North Korea’s UNC1069 Uses Fake Video Calls to Hijack Crypto

ID: d2e4b3ce-5c81-584a-975b-03e59d15790d

STIX ID: report--d2e4b3ce-5c81-584a-975b-03e59d15790d

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-04-19

Date Updated: 2026-05-05

Author: Ddos

...
...

Validin uncovered an active UNC1069 (Bluenoroff-linked) campaign that uses fake VC personas and convincing, attacker-controlled meeting sites to socially engineer crypto and Web3 professionals into running OS-specific payloads (Windows PowerShell/VBS RATs; macOS Mach-O/Perl; Linux ELF downloaders). The threat actors record meetings via browser APIs and reuse captured media and deepfakes in follow-on scams; researchers linked deployed malware (Cabbage RAT, NukeSped) to Lazarus, identified C2s/IPs (e.g., 45.61.157.248) and dozens of lookalike domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.