PUKCHONG
2024-06-12 • Google • Insights on Cyber Threats Targeting Users and Ent…
PUKCHONG is Google’s designation for a North Korean government-backed threat actor also tracked as UNC4899. Google described the cluster in June 2024 while reporting a campaign against cryptocurrency professionals in Brazil and other regions. The actor approached targets through social media with an apparent job opportunity at a well-known cryptocurrency company, first sending benign job-description and skills-questionnaire documents. Interested candidates were then directed to complete a coding test by downloading a project from GitHub. The project contained a trojanized Python application presented as a cryptocurrency-price tool; when specified conditions were met, it contacted attacker-controlled infrastructure to retrieve a second-stage payload. The operation combined patient recruiter impersonation, staged trust-building, developer-focused technical assessments, and weaponized source-code hosting to compromise people with access to cryptocurrency and financial-technology organizations.
-
34
Related Actors
-
2
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster