HomeSecurityNorth Korean hackers UNC1069 target crypto companies

North Korean hackers UNC1069 target crypto companies

North Korean hackers UNC1069 are targeting the crypto sector , with the aim of stealing sensitive data from Windows and macOS systems that will allow them to steal money.

UNC1069

“ The attack relied on a social engineering technique, involving a compromised Telegram account, a fake Zoom meeting, a ClickFix infection vector, and an AI-generated video to trick the victim, ” said Google Mandiant researchers Ross Inman and Adrian Hernandez .

UNC1069, which is estimated to have been active since at least April 2018, has been linked to various social engineering campaigns for financial gain, using fake meeting invitations and impersonating investors from reputable companies on Telegram. It is also monitored by the broader cybersecurity community under the aliases CryptoCore and MASAN.

In a report published last November, the Google Threat Intelligence Group (GTIG) highlighted the use of generative AI tools, such as Gemini, to create persuasive bait and other messages that aided in social engineering campaigns.

See also: From Ransomware to Permanent Access: The Rise of Digital Parasites

The group has also attempted to abuse Gemini to develop code to steal cryptocurrency, and has also leveraged deepfake images and videos, which mimic individuals in the crypto sector, to distribute a backdoor called BIGMACHO.

North Korean hackers UNC1069 target crypto companies

According to Google, since 2023, the team has improved its techniques and shifted its targeting from traditional financial (TradFi) services to the Web3, such as centralized exchanges (CEX), software developers at financial institutions, technology companies, etc.

In the latest detected intrusion, UNC1069 is reported to have deployed up to seven unique malware, including the new SILENCELIFT, DEEPBREATH, and CHROMEPUSH.

How do UNC1069's new attacks work?

It all starts when a victim is approached by the threat actor via Telegram. The attackers pose as venture capitalists and, in some cases, use compromised accounts of legitimate entrepreneurs and startup founders. Once contact is made, the threat actor uses Calendly to schedule a 30-minute meeting with the victim.

See also: New 'ZeroDayRAT' kit allows complete compromise of iOS and Android devices

The meeting link is designed to redirect the victim to a fake Zoom -like website (“zoom.uswe05[.]us”). In some cases, the links are shared directly via Telegram messages, often via the app’s hyperlink feature (to hide the phishing URLs).

Regardless of the method used, once the victim clicks on the link, a fake video call interface and the victim is prompted to turn on camera and enter name . Once the target joins the meeting, a screen that looks like a real Zoom meeting is displayed.

However, there is suspicion that the videos are either deepfakes or real recordings secretly recorded by other victims who had previously fallen victim to the same scam.

It is worth noting that Kaspersky is tracking the same campaign called GhostCall, which was documented in detail in October 2025.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“The camera footage was recorded without the victims’ knowledge. It was then uploaded to an infrastructure controlled by the attackers and reused to trick other victimsinto believing they were participating in a genuine live call,” the Russian security vendor noted. “When the video playback ends, the page smoothly transitions to displaying the user’s profile picture, maintaining the illusion of a live call.”

See also: A single prompt breaks down AI security in 15 major language models

North Korean hackers UNC1069 target crypto companies

The attack progresses to the next phase when the victim sees a fake error message about a supposed audio problem. They are then prompted to download and run a troubleshooting command (like ClickFix) to resolve the issue. In the case of macOS, the commands lead to the delivery of an AppleScript which, in turn, drops a malicious payload.

Dubbed WAVESHAPER, the malicious C++ executable is designed to collect system information and distribute a downloader, codenamed HYPERCALL. This is used to serve additional payloads:

  • A subsequent Golang backdoor component known as HIDDENCALL, which provides access to the compromised system via keyboard and deploys a Swift-based data miner called DEEPBREATH.
  • A second C++ downloader called SUGARLOADER, which is used to develop CHROMEPUSH.
  • A C/C++ backdoor referred to as SILENCELIFT, which sends system information to a command and control (C2) server.

DEEPBREATH is equipped to manipulate macOS' Transparency, Consent, and Control (TCC) database and gain access to the file system. From there, it can steal iCloud Keychain credentials and data from Google Chrome, Brave and Microsoft Edge, Telegram , and the Apple Notes app.

See also: Chinese hackers UNC3886 target Singaporean telecoms

North Korean hackers UNC1069 target crypto companies

Like DEEPBREATH, CHROMEPUSH also functions as a data stealer, except that it is written in C++ and deployed as a browser extension on Google Chrome and Brave. It is presented as a tool for editing Google Docs offline. It also has the ability to record keystrokes, steal usernames and passwords, and extract browser cookies.

“The volume of tools deployed on a single host suggests an extremely determined effort to harvest credentials, browser data, and session tokens to facilitate financial fraud,” Mandiant said. “While UNC1069 typically targets crypto startups, software developers, and venture capital firms, the deployment of multiple new malware alongside the well-known SUGARLOADER downloader marks a significant expansion of their capabilities.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS