UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering
2026-02-10 • Google •
Google Threat Intelligence describes a cryptocurrency-sector intrusion attributed to UNC1069, a financially motivated actor suspected with high confidence to have a North Korea nexus. The operation began through a compromised Telegram account, a Calendly link, a spoofed Zoom page, and ClickFix-style troubleshooting commands that caused the victim to execute a macOS infection chain. The intrusion deployed WAVESHAPER, HYPERCALL, HIDDENCALL, SUGARLOADER, SILENCELIFT, DEEPBREATH, and CHROMEPUSH to maintain access and steal Keychain data, browser cookies and logins, Telegram data, Apple Notes, keystrokes, screenshots, and session material. Notable infrastructure included zoom[.]uswe05[.]us, mylingocoin[.]com, supportzm[.]com, zmsupport[.]com, breakdream[.]com, dreamdie[.]com, cmailer[.]pro, and support-zoom[.]us, showing a focused data-harvesting operation for cryptocurrency theft and follow-on social engineering.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| YARA | G_Backdoor_WAVESHAPER_1 | 2026-02-10 | 2026-03-31 |
| HASH | c91725905b273e81e9cc6983a11c8d60 | 2026-02-10 | 2026-03-31 |
| DOMAIN | mylingocoin.com | 2026-02-10 | 2026-03-02 |
| DOMAIN | zmsupport.com | 2026-02-10 | 2026-03-02 |
| DOMAIN | dreamdie.com | 2026-02-10 | 2026-03-02 |
| DOMAIN | breakdream.com | 2026-02-10 | 2026-03-02 |
| DOMAIN | supportzm.com | 2026-01-29 | 2026-03-02 |
| YARA | G_Datamine_CHROMEPUSH_1 | 2026-02-10 | 2026-02-10 |
| YARA | G_Datamine_DEEPBREATH_1 | 2026-02-10 | 2026-02-10 |
| YARA | G_APTFIN_Downloader_SUGARLOADER… | 2026-02-10 | 2026-02-10 |
| YARA | G_APTFIN_Downloader_SUGARLOADER… | 2026-02-10 | 2026-02-10 |
| YARA | G_Backdoor_SILENCELIFT_1 | 2026-02-10 | 2026-02-10 |
| YARA | G_Downloader_HYPERCALL_1 | 2026-02-10 | 2026-02-10 |
| YARA | G_Backdoor_WAVESHAPER_2 | 2026-02-10 | 2026-02-10 |
| HASH | 3712793d3847dd0962361aa528fa124c | 2026-02-10 | 2026-02-10 |
| HASH | 4e4f2dfe143ba261fd8a18d1c4b58f2e | 2026-02-10 | 2026-02-10 |
| HASH | eb7635f4836c9e0aa4c315b18b051cb5 | 2026-02-10 | 2026-02-10 |
| URL | http://mylingocoin.com/audio/fi… | 2026-02-10 | 2026-02-10 |
| URL | http://cmailer.pro:80/upload | 2026-02-10 | 2026-02-10 |
| DOMAIN | cmailer.pro | 2026-02-10 | 2026-02-10 |