Mandiant: North Korean hacking groups are increasing social engineering attacks targeting cryptocurrency and fintech companies

ChainCatcher reports that, according to Cointelegraph, the U.S. cybersecurity firm Mandiant, a subsidiary of Google Cloud, has discovered that North Korea-linked threat groups are increasing social engineering attacks targeting cryptocurrency and fintech companies.

The threat group (codenamed UNC1069) has deployed seven malicious software suites, including newly discovered SILENCELIFT, DEEPBREATH, and CHROMEPUSH, aimed at obtaining sensitive data and stealing digital assets. The attackers exploit compromised Telegram accounts and use AI-generated deepfake videos to lure victims into fake Zoom meetings. Mandiant has been tracking this group since 2018, but advances in AI have helped the group expand its malicious activities since November 2025. In one intrusion, the attackers used stolen cryptocurrency founder Telegram accounts to initiate contact and employed a so-called ClickFix attack to trick victims into executing “troubleshooting” commands containing hidden instructions.

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Mt. Gox Bankruptcy Case May See Resolution with Proposed Bitcoin Hard Fork

Former Mt. Gox CEO Mark Karpeles has proposed a Bitcoin hard fork to recover 80,000 BTC stolen from the exchange over a decade ago. The hard fork would see the BTC, worth $5 billion and currently held by a single wallet, moved to a new address without the requirement of the original private k

CryptoNewsFlash3h ago

TRM Labs Report: AI-Driven Crypto Scams Increase 500% Year-over-Year by 2025

TRM Labs report indicates that artificial intelligence is reshaping digital financial crime, with illegal cryptocurrency flows expected to reach $158 billion by 2025. AI-driven scam cases have surged by 500%. Autonomous AI agents accelerate money laundering, lower the barriers to evasion, and lead to a compliance crisis. Legal liabilities are difficult to trace, requiring international cooperation to resolve jurisdiction conflicts.

GateNews5h ago

White-hat hackers help Foom Cash recover $1.84 million stolen funds, accounting for approximately 81% of the total funds.

Decentralized anonymous lottery protocol Foom Cash lost approximately $2.26 million due to a security vulnerability. White hat hackers intervened in time to recover $1.84 million. The issue stemmed from a misconfiguration of the Groth16 verifier. White hat hackers collaborated with security companies to protect the funds and received bounties and security fees.

GateNews5h ago

South Korea to investigate cryptocurrency photo leak and seed phrase incident causing $4.8 million in tax authority losses

The Korea National Tax Service apologized after publicly sharing a photo of a hardware wallet seed phrase, which led to the theft of $4.8 million worth of cryptocurrency. The government has requested police intervention and will strengthen regulations on digital asset management.

GateNews5h ago

Curve Finance: Investigation into sDOLA LlamaLend attack initiated; attacker profits are limited

Curve Finance has launched an investigation into the attack on Inverse Finance, confirming a loss of approximately $240,000. The cause of the attack is related to the sDOLA price oracle mechanism and the amount of sDOLA in the market. This incident serves as a reminder that more stringent measures are needed for treasury-type collateral management. The Curve team is currently assessing security measures to ensure the safety of similar markets in the future.

GateNews6h ago
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)