The post North Korea Linked Hackers Deploy New Crypto Malware appeared on BitcoinEthereumNews.com. North Korea-linked threat actors are escalating social engineeringThe post North Korea Linked Hackers Deploy New Crypto Malware appeared on BitcoinEthereumNews.com. North Korea-linked threat actors are escalating social engineering

North Korea Linked Hackers Deploy New Crypto Malware

North Korea-linked threat actors are escalating social engineering campaigns targeting cryptocurrency and fintech companies, deploying new malware designed to harvest sensitive data and steal digital assets.

In a recent campaign, a threat cluster tracked as UNC1069 deployed seven malware families aimed at capturing and exfiltrating victim data, according to a Tuesday report from Mandiant, a US cybersecurity company that operates under Google Cloud.

The campaign relied on social engineering schemes involving compromised Telegram accounts and fake Zoom meetings with deepfake videos generated through artificial intelligence tools.

“This investigation revealed a tailored intrusion resulting in the deployment of seven unique malware families, including a new set of tooling designed to capture host and victim data: SILENCELIFT, DEEPBREATH and CHROMEPUSH,” the report states.

Threat actor UNC1069, attack chain. Source: Mandiant/Google Cloud

Related: CZ sounds alarm as ‘SEAL’ team uncovers 60 fake IT workers linked to North Korea

Mandiant said the activity represents an expansion of the group’s operations, primarily targeting crypto companies, software developers and venture capital businesses.

The malware included two newly discovered, sophisticated data-mining viruses, named CHROMEPUSH and DEEPBREATH, which are designed to bypass key operating system components and gain access to personal data.

The threat actor with “suspected” North Korean ties has been tracked by Mandiant since 2018, but AI advancements helped the malicious actor scale up its operations and include “AI-enabled lures in active operations” for the first time in November 2025, according to a report at that time from the Google Threat Intelligence Group.

Cointelegraph contacted Mandiant for additional details regarding the attribution, but had not received a response by publication.

Related: Balancer hack shows signs of months-long planning by skilled attacker

Attackers are stealing crypto founder accounts to launch ClickFix attacks

In one intrusion outlined by Mandiant, attackers used a compromised Telegram account belonging to a crypto founder to initiate contact. The victim was invited to a Zoom meeting featuring a fabricated video feed in which the attacker claimed to be experiencing audio problems.

The attacker then directed the user to run troubleshooting commands in their system to fix the purported audio issue in a scam known as a ClickFix attack.

The provided troubleshooting commands embedded a hidden single command that initiated the infection chain, according to Mandiant.

UNC1069 victimology map. Source: Mandiant/Google Cloud

North Korea-linked illicit actors have been a persistent threat to both crypto investors and Web3-native companies.

In June 2025, four North Korean operatives infiltrated multiple crypto firms as freelance developers, stealing a cumulative $900,000 from these startups, Cointelegraph reported.

Earlier that year, the Lazarus Group was linked to the $1.4 billion hack of Bybit, one of the largest crypto thefts on record.

Magazine: Coinbase hack shows the law probably won’t protect you — Here’s why

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy

Source: https://cointelegraph.com/news/north-korean-hackers-malware-crypto-fintech-social-engineering?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
Cloud Logo
Cloud Price(CLOUD)
$0.04183
$0.04183$0.04183
+2.17%
USD
Cloud (CLOUD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Pi Network Enables Real Shopping with Picoin, Driving Demand and Utility

Pi Network Enables Real Shopping with Picoin, Driving Demand and Utility

Pi Network has emerged as a distinctive force in the cryptocurrency landscape by offering more than speculative trading. Unlike many digital coins that exist p
Share
Hokanews2026/02/12 13:58
Nigeria targets 95% digital literacy by 2030 – NITDA DG, Kashifu Inuwa

Nigeria targets 95% digital literacy by 2030 – NITDA DG, Kashifu Inuwa

The Director General of the National Information Technology Development Agency (NITDA), Kashifu Inuwa, has noted that Nigeria is… The post Nigeria targets 95% digital
Share
Technext2026/02/12 14:00
Music body ICMP laments “wilful” theft of artists’ work

Music body ICMP laments “wilful” theft of artists’ work

The post Music body ICMP laments “wilful” theft of artists’ work appeared on BitcoinEthereumNews.com. A major music industry group, ICMP, has lamented the use of artists’ work by AI companies, calling them guilty of “wilful” copyright infringement, as the battle between the tech firms and the arts industry continues. The Brussels-based group known as the International Confederation of Music Publishers (ICMP) comprises major record labels and other music industry professionals. Their voice adds to many others within the arts industry that have expressed displeasure at AI firms for using their creative work to train their systems without permission. ICMP accuses AI firms of deliberate copyright infringement ICMP director general John Phelan told AFP that big tech firms and AI-specific companies were involved in what he termed “the largest copyright infringement exercise that has been seen.” He cited the likes of OpenAI, Suno, Udio, and Mistral as some of the culprits. The ICMP carried out an investigation for nearly two years to ascertain how generative AI firms were using material by creatives to enrich themselves. The Brussels-based group is one of a number of industry bodies that span across news media and publishing to target the fast-growing AI sector over its use of content without paying any royalties. Suno and Udio, who are AI music generators, can produce tracks with voices, melodies, and musical styles that echo those of the original artists such as the Beatles, Depeche Mode, Mariah Carey, and the Beach boys. “What is legal or illegal is how the technologies are used. That means the corporate decisions made by the chief executives of companies matter immensely and should comply with the law,” Phelan told AFP. “What we see is they are engaged in wilful, commercial-scale copyright infringement.” Phelan. In June last year, a US trade group, the Recording Industry Association of America, filed a lawsuit against Suno and Udio. However, an exception…
Share
BitcoinEthereumNews2025/09/18 04:41