North Korea's UNC1069 Hammers Crypto Firms With AI
ID: 1f4ed264-4f2a-54a6-aa29-382b166518b9
STIX ID: report--1f4ed264-4f2a-54a6-aa29-382b166518b9
Feed Name: Dark Reading
Mandiant reports that UNC1069, a likely North Korean actor active since at least 2018, shifted toward targeting Web3 and cryptocurrency organizations using sophisticated social engineering: attackers used a compromised Telegram account, Calendly invites, and a spoofed Zoom deepfake video to convince victims to run commands that installed backdoors and data-mining tools to harvest credentials, browser and messaging data, and Apple Notes, enabling cryptocurrency theft and future campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
