UNC4469 is a DPRK-nexus threat actor associated with cryptocurrency theft in Web3 environments. The actor has been linked to the use of large numbers of blockchain smart contracts to facilitate theft of digital assets, reflecting tradecraft tailored to decentralized finance and related ecosystems. This activity aligns with North Korean financially motivated operations that leverage technical complexity and on-chain mechanisms to obscure malicious workflows and move stolen funds. Public reporting directly ties UNC4469 to the use of thousands of smart contracts in support of theft operations. The available high-confidence information supports characterization of the group as a crypto-focused intrusion actor with strong post-compromise and fund-exfiltration capability in blockchain contexts. Specific victim geography, sector concentration beyond cryptocurrency and Web3, and additional aliases or sub-groups are not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.