MASAN
2025-11-05 • Google • GTIG AI Threat Tracker: Advances in Threat Actor …
Google's Threat Intelligence Group reported in November 2025 on UNC1069, also tracked as MASAN, a North Korean state-sponsored threat actor that misuses Google's Gemini AI tools to support cryptocurrency theft operations intended to generate revenue for the regime. The group used Gemini to research cryptocurrency concepts and to help locate victims' cryptocurrency wallet application data, and attempted to use it to develop code for stealing cryptocurrency as well as to craft fraudulent instructions impersonating a software update in order to extract user credentials; Google disabled the account involved. Google's Threat Intelligence Group also observed the group using deepfake images and video lures impersonating individuals in the cryptocurrency industry as part of social engineering campaigns, prompting targets to download a fake Zoom SDK link that distributes its BIGMACHO backdoor. The group's operations rely on social engineering themes related to computer maintenance and credential harvesting.
-
34
Related Actors
-
1
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster