logo

North Korea's UNC1069 Hammers Crypto Firms With AI

ID: 1f4ed264-4f2a-54a6-aa29-382b166518b9

STIX ID: report--1f4ed264-4f2a-54a6-aa29-382b166518b9

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Mandiant reports that UNC1069, a likely North Korean actor active since at least 2018, shifted toward targeting Web3 and cryptocurrency organizations using sophisticated social engineering: attackers used a compromised Telegram account, Calendly invites, and a spoofed Zoom deepfake video to convince victims to run commands that installed backdoors and data-mining tools to harvest credentials, browser and messaging data, and Apple Notes, enabling cryptocurrency theft and future campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.