Google-owned Mandiant reported that threat actor UNC1069 targeted organizations in the cryptocurrency sector using newly observed tooling alongside AI-enabled social engineering. The campaign relied on deceptive outreach and impersonation tactics designed to build trust with victims, reflecting a broader shift toward using generative AI to improve the scale and plausibility of intrusion attempts against high-value financial targets.
Mandiant said the activity combined social engineering with custom or newly tracked attacker tooling to support compromise efforts against crypto-related entities. The report highlights the cryptocurrency industry as a continued focus for financially motivated threat activity, with attackers blending traditional intrusion tradecraft and AI-assisted lures to increase the likelihood of successful access and follow-on theft.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Google Cloud's Mandiant Threat Intelligence team published a report describing UNC1069 targeting the cryptocurrency sector using new tooling and AI-enabled social engineering. The reference does not provide earlier dated incident details, so the publication itself is the only extractable event.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.