logo

North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations

ID: b65a7963-d682-510e-a20e-8255dc1db20d

STIX ID: report--b65a7963-d682-510e-a20e-8255dc1db20d

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-02-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Google Mandiant and related reporting detail UNC1069 (aka CryptoCore/MASAN), a DPRK-linked actor targeting cryptocurrency industry victims via Telegram-based social engineering and fake Zoom meetings using AI/deepfake lures; the intrusion chain delivers a suite of new and known malware (WAVESHAPER, HYPERCALL, HIDDENCALL, DEEPBREATH, CHROMEPUSH, SILENCELIFT, SUGARLOADER) to harvest credentials, browser data, and session tokens to enable financial theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.