UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering
Mandiant Blog·vor 107 d·Reputabel
Written by: Ross Inman, Adrian Hernandez Introduction North Korean threat actors continue to evolve their tradecraft to target the cryptocurrency and decentralized finance (DeFi) verticals. Mandiant recently investigated an intrusion targeting a FinTech entity within this sector, attributed to UNC1069, a financially motivated threat actor active since at least 2018. This investigation revealed a tailored intrusion resulting in the deployment of seven unique malware families, including a new set of tooling designed to capture host and victim data: SILENCELIFT, DEEPBREATH and CHROMEPUSH. The int
Kategorien cybersecurity · government-security · unknown-it-category-15
Originalquelle / Advisory ↗Veröffentlicht
9.2.2026, 14:00:00
Abgerufen
27.5.2026, 04:13:32
Trust
reputable · 80/100
Sprache
en