North Korean threat actor UNC1069 has escalated targeted intrusions against the cryptocurrency and broader finance sector by combining highly tailored social engineering with new malware tooling. Victims are approached via professional messaging platforms (notably Telegram) using recruiter/executive pretexts and, in at least one case, a compromised account of another crypto executive to increase credibility. Lures include scheduling links (e.g., Calendly) that lead to spoofed video meetings; incident reporting described a call where the victim was shown what appeared to be a deepfake video of a crypto CEO, though responders noted they could not independently verify AI model use in that specific instance.
During the meeting, operators feign technical issues and direct the target to “fix” audio/video problems—an example of the ClickFix technique—by running provided troubleshooting steps. The embedded command sequence contains a malicious line that initiates infection; in the documented case, this resulted in macOS compromise and deployment of backdoors identified as WAVESHAPER and HYPERCALL, enabling follow-on tool delivery and persistence. Reporting attributes the campaign’s objective to credential/session token and browser data theft to facilitate financial theft (e.g., draining crypto wallets), and notes an expanded toolkit observed on victim hosts, including multiple distinct malware families (custom backdoors and browser extensions) intended to bypass defenses and maximize data extraction before detection.

See the actors and campaigns active against you right now.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-28, Arctic Wolf reported that BlueNoroff was targeting cryptocurrency executives through fake Zoom meetings that harvested webcam footage for reuse in later social-engineering lures, alongside ClickFix-style malware delivery. The report added new operational details, including compromise in under five minutes, persistence lasting 66 days in one case, and infrastructure comprising more than 80 typo-squatted Zoom and Teams domains.
In April 2026, Validin researchers linked UNC1069's fake-meeting malware campaign to the Axios NPM package compromise and reported overlaps with the Bluenoroff cluster previously discussed by Mandiant. This added a new technical and attributional connection between the social-engineering operation and broader North Korean intrusion activity.
In reporting published on 2026-04-14, researchers said UNC1069’s spoofed Zoom, Google Meet, and Microsoft Teams meeting pages could capture and stream victims’ microphone and camera feeds in real time and locally record them. The capability supports follow-on impersonation and social engineering against cryptocurrency, Web3, and financial-sector targets.
On 2026-04-13, Bitso/Quetzal researchers described a macOS-focused Famous Chollima campaign using hijacked Telegram accounts, fake Zoom/Meet/Teams meeting pages, and ClickFix-style terminal execution to deploy a malware chain including teamsSDK.bin, profiling implants, minst2.bin persistence, and the macrasv2 stealer. The report also disclosed operational security failures in the attackers' infrastructure, including an unauthenticated Go C2 /info endpoint and an exposed Telegram Bot API token that could enable disruption.
On February 10, 2026, Mandiant's findings were publicly reported, attributing the campaign to UNC1069 and detailing its use of AI-enabled social engineering, deepfake video, ClickFix execution, and newly identified malware. The disclosure highlighted the group's intensified focus on cryptocurrency and finance-sector victims.
Following initial access in the investigated intrusion, UNC1069 deployed an unusually large toolset on the victim host, including up to seven malware families such as WAVESHAPER, HYPERCALL, SUGARLOADER, SILENCELIFT, DEEPBREATH, and CHROMEPUSH. The tooling was used to steal credentials, browser and session data, Telegram and Apple Notes data, keystrokes, and other information to support cryptocurrency theft and future impersonation.
In the incident investigated by Mandiant, attackers used a compromised cryptocurrency executive's Telegram account, a Calendly invite, and a spoofed Zoom meeting featuring an apparent deepfake CEO video to trick a victim into running ClickFix-style commands. The commands initiated infection on macOS, with reporting indicating the broader campaign also targeted Windows systems.
Reports state that during 2025 UNC1069 was active against financial services and cryptocurrency-related verticals such as payments, brokerage, and wallet infrastructure. This reflects a continued expansion and concentration of the group's financially motivated operations.
By 2023, UNC1069 had moved away from more traditional spear-phishing and traditional financial-sector targets toward Web3 entities, including exchanges, software developers, venture capital personnel, and other cryptocurrency-related organizations. Multiple reports describe this as a strategic evolution in the group's targeting.
Mandiant says the North Korea-linked, financially motivated threat actor UNC1069 has been active since at least 2018. This establishes the earliest known baseline for the group's operations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 67 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
17 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcedarkreading.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.