UNC1069

2023-04-18 • MandiantM-Trends 2023: Cybersecurity Insights From the Fr…

UNC1069 is Google Threat Intelligence Group’s designation for a financially motivated actor assessed with high confidence to have a North Korean nexus. Active since at least 2018, the group shifted toward Web3 targets by 2023, including cryptocurrency exchanges, financial-software developers, venture-capital firms, technology companies, and wallet and payment providers. Its operators compromise trusted messaging accounts, impersonate executives, arrange fake Zoom meetings, and use ClickFix-style troubleshooting instructions to convince victims to execute malware. A 2026 intrusion combined a reported deepfake video with macOS backdoors, downloaders, and data miners including WAVESHAPER, HYPERCALL, HIDDENCALL, SUGARLOADER, DEEPBREATH, CHROMEPUSH, and SILENCELIFT. These tools harvested Keychain credentials, browser passwords, cookies, Telegram data, notes, files, screenshots, and keystrokes while establishing persistence and hands-on-keyboard access. The group uses collected data both for direct cryptocurrency theft and to enable further tailored social engineering.

Related Actors

Related Reports in This Cluster

Top Authors

View UNC1069 reports only

View UNC1069 reports only