Cryptocurrency Sector Targeted with New Tooling and AI-Enabled Social Engineering
North Korean threat actor UNC1069 has evolved its tactics to target the cryptocurrency and decentralized finance sectors. In a recent intrusion, they deployed seven unique malware families, including new tools SILENCELIFT, DEEPBREATH, and CHROMEPUSH, designed to capture host and victim data. The attack utilized social engineering involving a compromised Telegram account, fake Zoom meeting, and reported AI-generated video. UNC1069 has shifted from spear-phishing to targeting Web3 industry entities like centralized exchanges, software developers, and venture capital firms. The intrusion demonstrated sophisticated techniques to bypass macOS security features and harvest credentials, browser data, and cryptocurrency information. This marks a significant expansion in UNC1069's capabilities and highlights their focus on financial theft and fueling future social engineering campaigns.
Pulse ID: 698a3590b78fb5ef2d81d5f1
Pulse Link: https://otx.alienvault.com/pulse/698a3590b78fb5ef2d81d5f1
Pulse Author: AlienVault
Created: 2026-02-09 19:29:20
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #ICS #InfoSec #Korea #Mac #MacOS #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #SocialEngineering #SpearPhishing #Telegram #Web3 #Zoom #bot #cryptocurrency #developers #AlienVault