North Korean Hacker Group Deploys Malware Targeting Crypto and Fintech Companies
Odaily News According to Mandiant, a US cybersecurity company under Google Cloud, North Korea-linked threat actors are intensifying social engineering attacks targeting cryptocurrency and fintech companies.
The threat group (codenamed UNC1069) deployed seven malware packages, including the newly discovered SILENCELIFT, DEEPBREATH, and CHROMEPUSH, aimed at obtaining sensitive data and stealing digital assets. Attackers used compromised Telegram accounts and AI-generated deepfake videos to lure victims into fake Zoom meetings.
Mandiant has been tracking this group since 2018, but advancements in AI have helped the group scale up its malicious activities since November 2025. In one intrusion incident, attackers used a stolen Telegram account belonging to a cryptocurrency founder to initiate contact, tricking victims into executing "troubleshooting" instructions containing hidden commands through a so-called ClickFix attack. (Cointelegraph)
