UNC1069 is Google Threat Intelligence Group’s designation for a financially motivated actor assessed with high confidence to have a North Korean nexus. Active since at least 2018, the group shifted toward Web3 targets by 2023, including cryptocurrency exchanges, financial-software developers, venture-capital firms, technology companies, and wallet and payment providers. Its operators compromise trusted messaging accounts, impersonate executives, arrange fake Zoom meetings, and use ClickFix-style troubleshooting instructions to convince victims to execute malware. A 2026 intrusion combined a reported deepfake video with macOS backdoors, downloaders, and data miners including WAVESHAPER, HYPERCALL, HIDDENCALL, SUGARLOADER, DEEPBREATH, CHROMEPUSH, and SILENCELIFT. These tools harvested Keychain credentials, browser passwords, cookies, Telegram data, notes, files, screenshots, and keystrokes while establishing persistence and hands-on-keyboard access. The group uses collected data both for direct cryptocurrency theft and to enable further tailored social engineering.
Zerion
#Zerion • 2026-04
The Zerion security incident involved a targeted AI-enabled social engineering attack against a team member’s device, which resulted in the compromise of active sessions, credentials, and private keys to internal hot wallets, allowing attackers to steal approximately $100K in company funds; however, the impact was contained due to strong architectural isolation, with no user funds, apps, or backend infrastructure affected, as Zerion’s self-custodial model prevented access to user assets, and production systems remained segregated; in response, the team rapidly secured infrastructure, took the web app offline to prevent malicious deployments, rotated all credentials and keys, audited employee devices, and collaborated with security partners to track attacker wallets, highlighting that even well-secured systems remain vulnerable to advanced, AI-driven human-targeted attacks, with key lessons centered on strengthening authentication, device security, and employee awareness against increasingly sophisticated social engineering threats.
-
1
Related Reports
-
1
Affected Countries
-
4
Months Since