North Korea-Linked UNC1069 Targets Cryptocurrency Sector with AI-Generated Video and Malware
Summary
Hide ▲
Show ▼
The Lazarus Group, a North Korea-linked threat actor, has expanded its operations to target European defense companies in 2025, leveraging a coordinated Operation DreamJob campaign. The attack involved fake recruitment lures and the deployment of various malware, including the ScoringMathTea RAT. This campaign follows earlier attacks on a decentralized finance (DeFi) organization in 2024, where the group deployed multiple cross-platform malware variants, including PondRAT, ThemeForestRAT, and RemotePE. In 2026, North Korean hackers have been observed using AI-generated video and the ClickFix technique to deliver malware for macOS and Windows to targets in the cryptocurrency sector. The threat actor's goal is financial, as suggested by the role of the tools used in an attack on a fintech company investigated by Google's Mandiant researchers. The attack had a strong social engineering component, with the victim being contacted over Telegram from a compromised executive account. The hackers used a Calendly link to a spoofed Zoom meeting page and showed a deepfake video of a CEO to facilitate the attack. Mandiant researchers found seven distinct macOS malware families attributed to UNC1069, a threat group they've been tracking since 2018. UNC1069 has been active since at least April 2018 and is also tracked under the monikers CryptoCore and MASAN. The group has used generative AI tools like Gemini to produce lure material and other messaging related to cryptocurrency. They have attempted to misuse Gemini to develop code to steal cryptocurrency and have leveraged deepfake images and video lures mimicking individuals in the cryptocurrency industry. The group has shifted from spear-phishing techniques and traditional finance (TradFi) targeting towards the Web3 industry since at least 2023, targeting centralized exchanges (CEX), software developers at financial institutions, high-technology companies, and individuals at venture capital funds. In the latest intrusion documented by Google's threat intelligence division, UNC1069 deployed as many as seven unique malware families, including several new malware families such as SILENCELIFT, DEEPBREATH, and CHROMEPUSH. The attack involved a social engineering scheme using a compromised Telegram account, a fake Zoom meeting, a ClickFix infection vector, and reported usage of AI-generated video to deceive the victim. The group used a fake website masquerading as Zoom to deceive victims and reused videos of previous victims to deceive new victims. The attack proceeded with a ClickFix-style troubleshooting command to deliver malware, leading to the deployment of various malicious components designed to gather system information, provide hands-on keyboard access, and steal sensitive data.
Timeline
-
11.02.2026 00:17 4 articles · 1d ago
UNC1069 Targets Cryptocurrency Sector with AI-Generated Video and Malware
The article provides additional details on the attack, including the use of a compromised cryptocurrency executive's Telegram account to target a secondary victim. The attackers sent a Calendly link to schedule a 30-minute meeting that directed to a spoofed Zoom meeting hosted on the threat actor's infrastructure. The spoofed Zoom call was a deepfake video posing as another cryptocurrency executive. The attackers tricked the victim into troubleshooting audio issues by running malicious commands on their macOS device. The command installed a backdoor that enabled follow-on activity, including deployment of a downloader for additional tooling and a second backdoor. The additional tools included two data miners to seize keychain credentials, browser data, Telegram user data, and Apple Notes user data. UNC1069 uses large language models (LLMs) like Gemini to conduct research and develop tooling for attacks.
Show sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
23.10.2025 15:38 5 articles · 3mo ago
Lazarus Group Targets European Defense Companies in Operation DreamJob
The campaign began in late March 2025. The attackers used a trojanized PDF reader to deliver malware. The campaign exhibits overlaps with clusters tracked as DeathNote, NukeSped, Operation In(ter)ception, and Operation North Star. The campaign could be focused on collecting information on weapon systems deployed in Ukraine, as well as gathering information to perfect designs and processes. At least two of the victims are heavily involved in the development of UAV technology, with one making critical drone components and the other building UAV-related software.
Show sources
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
-
02.09.2025 19:39 3 articles · 5mo ago
Lazarus Group Deploys Multiple RATs in DeFi Sector Campaign
In 2024, the Lazarus Group targeted a DeFi organization using a social engineering campaign. The attack involved the deployment of PondRAT, ThemeForestRAT, and RemotePE. The attackers used various tools for discovery, credential harvesting, and proxy connections, eventually transitioning to stealthier RATs for more complex tasks. The campaign began with impersonation on Telegram and fake scheduling websites, leading to the compromise of an employee's system.
Show sources
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE — thehackernews.com — 02.09.2025 19:39
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
Information Snippets
-
The Lazarus Group targeted a DeFi organization in 2024.
First reported: 02.09.2025 19:394 sources, 6 articlesShow sources
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE — thehackernews.com — 02.09.2025 19:39
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
-
The attack began with social engineering on Telegram and fake scheduling websites.
First reported: 02.09.2025 19:395 sources, 7 articlesShow sources
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE — thehackernews.com — 02.09.2025 19:39
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
PerfhLoader was used to deploy PondRAT, a stripped-down variant of POOLRAT.
First reported: 02.09.2025 19:391 source, 1 articleShow sources
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE — thehackernews.com — 02.09.2025 19:39
-
PondRAT was used in combination with ThemeForestRAT for approximately three months.
First reported: 02.09.2025 19:391 source, 1 articleShow sources
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE — thehackernews.com — 02.09.2025 19:39
-
ThemeForestRAT shares similarities with RomeoGolf, used in the 2014 Sony Pictures Entertainment attack.
First reported: 02.09.2025 19:391 source, 1 articleShow sources
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE — thehackernews.com — 02.09.2025 19:39
-
RemotePE, a more advanced RAT, was deployed for high-value targets.
First reported: 02.09.2025 19:391 source, 1 articleShow sources
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE — thehackernews.com — 02.09.2025 19:39
-
The attackers used various tools for discovery, credential harvesting, and proxy connections.
First reported: 02.09.2025 19:392 sources, 2 articlesShow sources
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE — thehackernews.com — 02.09.2025 19:39
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
-
The attack involved the use of Mimikatz, FRPC, and proxy programs like MidProxy and Proxy Mini.
First reported: 02.09.2025 19:392 sources, 2 articlesShow sources
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE — thehackernews.com — 02.09.2025 19:39
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
-
PondRAT communicates over HTTP(S) with a hard-coded command-and-control (C2) server.
First reported: 02.09.2025 19:391 source, 1 articleShow sources
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE — thehackernews.com — 02.09.2025 19:39
-
ThemeForestRAT can execute a wide range of commands, including file operations, shellcode injection, and process spawning.
First reported: 02.09.2025 19:391 source, 1 articleShow sources
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE — thehackernews.com — 02.09.2025 19:39
-
The Lazarus Group targeted European defense companies in 2025.
First reported: 23.10.2025 15:384 sources, 4 articlesShow sources
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
Operation DreamJob involved fake recruitment lures to compromise defense sector organizations.
First reported: 23.10.2025 15:384 sources, 4 articlesShow sources
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The campaign targeted UAV technology developers in Southeastern and Central Europe.
First reported: 23.10.2025 15:384 sources, 4 articlesShow sources
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The attack used trojanized open-source applications and plugins to deliver malware.
First reported: 23.10.2025 15:384 sources, 4 articlesShow sources
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The ScoringMathTea RAT was used to establish communication with the C2 infrastructure.
First reported: 23.10.2025 15:384 sources, 4 articlesShow sources
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
BinMergeLoader (MISTPEN) was used to retrieve additional payloads via Microsoft Graph API.
First reported: 23.10.2025 15:382 sources, 2 articlesShow sources
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
-
The ScoringMathTea RAT supports 40 commands, providing broad operational versatility.
First reported: 23.10.2025 15:382 sources, 2 articlesShow sources
- North Korean Lazarus hackers targeted European defense companies — www.bleepingcomputer.com — 23.10.2025 15:38
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
-
The campaign targeted three European firms: a metal engineering company, an aircraft components manufacturer, and a defense contractor.
First reported: 23.10.2025 16:303 sources, 3 articlesShow sources
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The malware was delivered through a series of droppers and loaders disguised as legitimate software components, including manipulated open-source projects from GitHub.
First reported: 23.10.2025 16:303 sources, 3 articlesShow sources
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The key malicious file, DroneEXEHijackingLoader.dll, indicates the campaign specifically sought UAV-related data.
First reported: 23.10.2025 16:303 sources, 3 articlesShow sources
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The timing of the attacks coincides with North Korean soldiers supporting Russian operations in Ukraine.
First reported: 23.10.2025 16:303 sources, 3 articlesShow sources
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The attackers introduced new elements to their toolset in 2025, including trojanized open-source applications such as TightVNC Viewer and MuPDF.
First reported: 23.10.2025 16:302 sources, 2 articlesShow sources
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
-
The attackers used new loaders and downloaders built from DirectX Wrappers and Notepad++ plugins.
First reported: 23.10.2025 16:302 sources, 2 articlesShow sources
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
-
ESET concluded that this latest campaign underscores the persistent risk faced by the defense sector, particularly those engaged in UAV research.
First reported: 23.10.2025 16:302 sources, 2 articlesShow sources
- Lazarus Group’s Operation DreamJob Targets European Defense Firms — www.infosecurity-magazine.com — 23.10.2025 16:30
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
-
The campaign began in late March 2025.
First reported: 23.10.2025 18:292 sources, 2 articlesShow sources
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The attackers used a trojanized PDF reader to deliver malware.
First reported: 23.10.2025 18:292 sources, 2 articlesShow sources
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The attackers used a sophisticated downloader codenamed BinMergeLoader to fetch additional payloads via Microsoft Graph API.
First reported: 23.10.2025 18:291 source, 1 articleShow sources
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
-
The campaign exhibits overlaps with clusters tracked as DeathNote, NukeSped, Operation In(ter)ception, and Operation North Star.
First reported: 23.10.2025 18:292 sources, 2 articlesShow sources
- North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets — thehackernews.com — 23.10.2025 18:29
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
Lazarus Group, also known as Diamond Sleet, Hidden Cobra, and Zinc, has been active since at least 2009.
First reported: 24.10.2025 16:242 sources, 2 articlesShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
-
The group has been engaging in intrusion campaigns targeting the aerospace, defense, engineering, media and entertainment, and technology sectors.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The attackers used a trojanized open-source PDF reader to deploy the ScoringMathTea RAT.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The campaign could be focused on collecting information on weapon systems deployed in Ukraine.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The attacks occurred while North Korean soldiers were active in Russia to help repel Ukraine’s offensive in the Kursk region.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The victim organizations produce materials that North Korea manufactures domestically.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The intrusions could be aimed at gathering information to perfect designs and processes.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
At least two of the victims are heavily involved in the development of UAV technology.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
One victim makes critical drone components, while the other is engaged in building UAV-related software.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
North Korea is investing heavily in domestic drone manufacturing capabilities.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
North Korea is receiving assistance from Russia to produce its version of the Iranian-made Shahed drone.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
North Korea has developed its domestic UAV capabilities through reverse engineering and the theft of intellectual property.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
The Saetbyol-4 and Saetbyol-9 drones are copies of the Northrop Grumman RQ-4 Global Hawk and General Atomics MQ-9 Reaper, respectively.
First reported: 24.10.2025 16:241 source, 1 articleShow sources
- North Korean Hackers Aim at European Drone Companies — www.securityweek.com — 24.10.2025 16:24
-
North Korean hackers are using AI-generated video and the ClickFix technique to deliver malware for macOS and Windows to targets in the cryptocurrency sector.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The threat actor's goal is financial, as suggested by the role of the tools used in an attack on a fintech company investigated by Google's Mandiant researchers.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
Mandiant researchers found seven distinct macOS malware families attributed to UNC1069, a threat group they've been tracking since 2018.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The attack had a strong social engineering component as the victim was contacted over the Telegram messaging service from a compromised account of an executive at a cryptocurrency company.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The hackers shared a Calendly link that took the victim to a spoofed Zoom meeting page on the attacker's infrastructure.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The hackers showed a deepfake video of a CEO at another cryptocurrency company.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The attacker instructed the victim to troubleshoot the problems using commands present on a webpage.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
Mandiant found commands on the page for both Windows and macOS that would start the infection chain.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
Huntress researchers documented a similar attack method in mid-2025 and attributed it to the BlueNoroff group, another North Korean adversary.
First reported: 11.02.2026 00:173 sources, 3 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
Mandiant researcher found evidence of AppleScript execution once the infection chain started, but could not recover the contents of the payload, followed by deploying a malicious Mach-O binary.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
In the next stage, the attacker executed seven distinct malware families: WAVESHAPER, HYPERCALL, HIDDENCALL, SILENCELIFT, DEEPBREATH, SUGARLOADER, and CHROMEPUSH.
First reported: 11.02.2026 00:172 sources, 2 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
-
Of the malware found, SUGARLOADER has the most detections on the VirusTotal scanning platform, followed by WAVESHAPER, which is flagged by just two products.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
Mandiant says that SILENCELIFT, DEEPBREATH, and CHROMEPUSH represent a new set of tooling for the threat actor.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The researchers describe as unusual the volume of malware deployed on a host against a single individual.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
This confirms a targeted attack focused on collecting as much data as possible for two reasons: "cryptocurrency theft and fueling future social engineering campaigns by leveraging victim’s identity and data."
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
Since 2018, UNC1069 has demonstrated its ability to evolve by adopting new techniques and tools.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
In 2023, the bad actor switched to targets in the Web3 industry (centralized exchanges, developers, venture capital funds).
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
Last year, the threat actor changed its target to financial services and the cryptocurrency industry in verticals such as payments, brokerage, and wallet infrastructure.
First reported: 11.02.2026 00:174 sources, 4 articlesShow sources
- North Korean hackers use new macOS malware in crypto-theft attacks — www.bleepingcomputer.com — 11.02.2026 00:17
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has been active since at least April 2018.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 is also tracked under the monikers CryptoCore and MASAN.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has used generative AI tools like Gemini to produce lure material and other messaging related to cryptocurrency.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has attempted to misuse Gemmini to develop code to steal cryptocurrency.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has leveraged deepfake images and video lures mimicking individuals in the cryptocurrency industry.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has distributed a backdoor called BIGMACHO to victims by passing it off as a Zoom software development kit (SDK).
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has shifted from spear-phishing techniques and traditional finance (TradFi) targeting towards the Web3 industry since at least 2023.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has targeted centralized exchanges (CEX), software developers at financial institutions, high-technology companies, and individuals at venture capital funds.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has deployed as many as seven unique malware families, including several new malware families such as SILENCELIFT, DEEPBREATH, and CHROMEPUSH.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has used a fake website masquerading as Zoom (zoom.uswe05[.]us) to deceive victims.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has reused videos of previous victims to deceive new victims, making them believe they were participating in a genuine live call.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has used a ClickFix-style troubleshooting command to deliver malware to victims.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has used an AppleScript to drop a malicious Mach-O binary on macOS systems.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has used a malicious C++ executable called WAVESHAPER to gather system information and distribute a Go-based downloader codenamed HYPERCALL.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has used a Golang backdoor component known as HIDDENCALL to provide hands-on keyboard access to the compromised system.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has used a Swift-based data miner called DEEPBREATH to manipulate macOS's Transparency, Consent, and Control (TCC) database.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has used a second C++ downloader called SUGARLOADER to deploy CHROMEPUSH.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has used a minimalist C/C++ backdoor referred to as SILENCELIFT to send system information to a command-and-control (C2) server.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has used DEEPBREATH to steal iCloud Keychain credentials, and data from Google Chrome, Brave, and Microsoft Edge, Telegram, and the Apple Notes application.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has used CHROMEPUSH as a data stealer, written in C++, to record keystrokes, observe username and password inputs, and extract browser cookies.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 has deployed multiple new malware families alongside the known downloader SUGARLOADER, marking a significant expansion in their capabilities.
First reported: 11.02.2026 08:503 sources, 3 articlesShow sources
- North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations — thehackernews.com — 11.02.2026 08:50
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The attackers used a hijacked Telegram profile of a cryptocurrency executive to build trust and rapport before sending a calendar invite to join a meeting.
First reported: 11.02.2026 18:352 sources, 2 articlesShow sources
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The meeting was designed to look like Zoom but was hosted on attacker-controlled infrastructure.
First reported: 11.02.2026 18:352 sources, 2 articlesShow sources
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The victim was faced with a deepfake of the cryptocurrency executive during the meeting.
First reported: 11.02.2026 18:352 sources, 2 articlesShow sources
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The attacker claimed the victim was having audio issues and offered a solution to help, which was a ClickFix attack.
First reported: 11.02.2026 18:352 sources, 2 articlesShow sources
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The attackers dropped malicious files onto the device, including Waveshaper and Hypercall backdoors.
First reported: 11.02.2026 18:352 sources, 2 articlesShow sources
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The attackers installed information stealer malware and a data miner, Deepbreath and CHROMEPUSH, to gain further control and persistence over the machine.
First reported: 11.02.2026 18:352 sources, 2 articlesShow sources
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The malware allowed the attackers to steal credentials from the user's Keychain, browser data from Chrome, Brave, and Edge, user data from two different versions of Telegram, and user data from Apple Notes.
First reported: 11.02.2026 18:352 sources, 2 articlesShow sources
- North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms — www.infosecurity-magazine.com — 11.02.2026 18:35
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 used a compromised cryptocurrency executive's Telegram account to target a secondary victim.
First reported: 11.02.2026 23:561 source, 1 articleShow sources
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The attackers sent a Calendly link to schedule a 30-minute meeting that directed to a spoofed Zoom meeting hosted on the threat actor's infrastructure.
First reported: 11.02.2026 23:561 source, 1 articleShow sources
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The spoofed Zoom call was a deepfake video posing as another cryptocurrency executive.
First reported: 11.02.2026 23:561 source, 1 articleShow sources
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The attackers tricked the victim into troubleshooting audio issues by running malicious commands on their macOS device.
First reported: 11.02.2026 23:561 source, 1 articleShow sources
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The command installed a backdoor that enabled follow-on activity, including deployment of a downloader for additional tooling and a second backdoor.
First reported: 11.02.2026 23:561 source, 1 articleShow sources
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
The additional tools included two data miners to seize keychain credentials, browser data, Telegram user data, and Apple Notes user data.
First reported: 11.02.2026 23:561 source, 1 articleShow sources
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
-
UNC1069 uses large language models (LLMs) like Gemini to conduct research and develop tooling for attacks.
First reported: 11.02.2026 23:561 source, 1 articleShow sources
- North Korea's UNC1069 Hammers Crypto Firms With AI — www.darkreading.com — 11.02.2026 23:56
Similar Happenings
Bizarre Bazaar Campaign Exploits Exposed LLM Endpoints
A cybercrime operation named 'Bizarre Bazaar' is actively targeting exposed or poorly authenticated LLM (Large Language Model) service endpoints. Over 35,000 attack sessions were recorded in 40 days, involving unauthorized access to steal computing resources, resell API access, exfiltrate data, and pivot into internal systems. The campaign highlights the emerging threat of 'LLMjacking' attacks, where attackers exploit misconfigurations in LLM infrastructure to monetize access through cryptocurrency mining and darknet markets. The SilverInc service, marketed on Telegram and Discord, resells access to more than 50 AI models in exchange for cryptocurrency or PayPal payments. A recent investigation by SentinelOne SentinelLABS and Censys revealed 175,000 unique Ollama hosts across 130 countries, many of which are configured with tool-calling capabilities, increasing the risk of LLMjacking attacks.
Multi-Stage AitM Phishing and BEC Campaigns Target Energy Sector
Microsoft has identified a multi-stage adversary-in-the-middle (AitM) phishing and business email compromise (BEC) campaign targeting organizations in the energy sector. The attackers abused SharePoint file-sharing services to deliver phishing payloads and created inbox rules to maintain persistence and evade detection. The campaign involved leveraging compromised internal identities to conduct large-scale phishing attacks within and outside the victim organizations. Additionally, the AgreeTo Outlook add-in was hijacked and turned into a phishing kit, stealing over 4,000 Microsoft account credentials. The threat actor deployed a fake Microsoft sign-in page, password collection page, exfiltration script, and redirect, exploiting the add-in's ReadWriteItem permissions. This is the first known instance of malware found on the official Microsoft Marketplace. The add-in was abandoned by its developer and the attacker exploited the abandoned domain to serve the phishing kit. The incident highlights the need for better monitoring of add-ins and their associated URLs.
PluggyApe Backdoor Targets Ukraine's Defense Forces in Charity-Themed Campaign
Ukraine's Defense Forces were targeted in a charity-themed malware campaign between October and December 2025. The campaign delivered the PluggyApe backdoor, likely deployed by the Russian threat group Void Blizzard (Laundry Bear). The attacks began with instant messages over Signal or WhatsApp, directing recipients to malicious websites posing as charitable foundations. These sites distributed password-protected archives containing PluggyApe payloads. The malware profiles the host, sends victim information to attackers, and waits for further commands. The campaign highlights the increasing use of mobile devices as prime targets due to their poor protection and monitoring. Additionally, the Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of new cyber attacks targeting its defense forces with malware known as PLUGGYAPE between October and December 2025. The threat actor is believed to be active since at least April 2024. The malware is written in Python and establishes communication with a remote server over WebSocket or Message Queuing Telemetry Transport (MQTT). The command-and-control (C2) addresses are retrieved from external paste services such as rentry[.]co and pastebin[.]com, where they are stored in base64-encoded form.
GoBruteforcer Botnet Expands Attacks on Linux Servers
The GoBruteforcer botnet has expanded its attacks to target databases of cryptocurrency and blockchain projects, exploiting weak credentials and misconfigured software. Over 50,000 publicly accessible servers are vulnerable, with the botnet turning compromised machines into scanning and attack nodes. A more capable variant of the malware, written in Go, was observed in mid-2025, featuring heavier obfuscation and stronger persistence. The botnet exploits predictable usernames and weak defaults, targeting exposed services like XAMPP and WordPress admin panels. Financial motives are evident, with tools found to scan TRON balances and sweep tokens on TRON and Binance Smart Chain. On-chain analysis confirms some successful attacks, though most affected addresses held small balances. The botnet uses common operational usernames such as 'myuser' and 'appuser', and common passwords like '123321' and 'testing'. GoBruteforcer campaigns tweak the credential sets depending on the target, including cryptocurrency-themed usernames and passwords.
Pro-Russia Hacktivists Target Critical Infrastructure with Low-Sophistication Attacks
Pro-Russia hacktivist groups are conducting opportunistic, low-sophistication cyberattacks against U.S., UK, and global critical infrastructure. These attacks target a wide range of sectors, including water treatment facilities, food production, energy systems, and local government bodies, using easily repeatable methods. The groups exploit minimally secured, internet-facing virtual network computing (VNC) connections to gain unauthorized access to operational technology (OT) control devices. The joint advisory from CISA, FBI, NSA, and global partners, along with a recent warning from the UK National Cyber Security Centre (NCSC), urges immediate action to mitigate these threats. The advisory highlights the use of basic methods to target supervisory control and data acquisition (SCADA) networks, sometimes combined with DDoS attacks. The cumulative impact of these activities poses a persistent and disruptive threat to essential services. According to a new report, groups such as Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), and Sector16 are using simple reconnaissance tools and common password-guessing techniques to reach internet-facing human-machine interfaces. These groups have led to physical impacts in some cases, including temporary loss of view and costly manual recovery efforts. The NCSC warns of continued malicious activity from Russian-aligned hacktivist groups targeting critical infrastructure and local government organizations in the UK with disruptive denial-of-service (DDoS) attacks. The NCSC notes that NoName057(16) operates the DDoSia project, a platform that allows volunteers to contribute computing resources to carry out crowdsourced DDoS attacks and receive monetary rewards or recognition from the community. Operation Eastwood disrupted NoName057(16)'s activity in mid-July 2025 by arresting two members of the group, issuing eight arrest warrants, and taking down 100 servers. Despite these efforts, the group has returned to action, highlighting the evolving threat they pose. Recent developments indicate that attackers are growing more interested in and accustomed to dealing with industrial machines, potentially leading to more sophisticated OT attacks. Ric Derbyshire, principal security engineer at Orange Cyberdefense, will demonstrate 'living-off-the-plant' attacks at the RSA Conference 2026, which require a holistic understanding of the physical process, OT systems, network architecture, security controls, and human interactions.