PortsuppeApp
SearchSourcesAboutDE/EN

UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering

Mandiant Blog·107d·Reputable

Written by: Ross Inman, Adrian Hernandez Introduction North Korean threat actors continue to evolve their tradecraft to target the cryptocurrency and decentralized finance (DeFi) verticals. Mandiant recently investigated an intrusion targeting a FinTech entity within this sector, attributed to UNC1069, a financially motivated threat actor active since at least 2018. This investigation revealed a tailored intrusion resulting in the deployment of seven unique malware families, including a new set of tooling designed to capture host and victim data: SILENCELIFT, DEEPBREATH and CHROMEPUSH. The int

Categories cybersecurity · government-security · unknown-it-category-15
Original source / advisory
Published
2/9/2026, 2:00:00 PM
Fetched
5/27/2026, 4:13:32 AM
Trust
reputable · 80/100
Language
en