North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations
UNC1069, a threat actor with ties to North Korea, has been seen targeting the cryptocurrency industry in an attempt to obtain private information from Windows and macOS devices in order to facilitate financial theft.
According to Google Mandiant experts Ross Inman and Adrian Hernandez, the breach used a social engineering approach that included a hacked Telegram account, a phony Zoom meeting, a ClickFix infection vector, and reported use of AI-generated video to trick the victim.
UNC1069, which has been active since at least April 2018, has a history of using phony meeting invites and impersonating investors from respectable companies on Telegram to carry out social engineering efforts for financial benefit. The larger cybersecurity community also keeps tabs on it under the names MA...










