UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering

2026-02-10 Google

https://cloud.google.com/blog/topics/threat-intelligence/unc1069-targets-cryptocurrency-ai-social-engineering

Thumbnail for UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering

Google Threat Intelligence describes a cryptocurrency-sector intrusion attributed to UNC1069, a financially motivated actor suspected with high confidence to have a North Korea nexus. The operation began through a compromised Telegram account, a Calendly link, a spoofed Zoom page, and ClickFix-style troubleshooting commands that caused the victim to execute a macOS infection chain. The intrusion deployed WAVESHAPER, HYPERCALL, HIDDENCALL, SUGARLOADER, SILENCELIFT, DEEPBREATH, and CHROMEPUSH to maintain access and steal Keychain data, browser cookies and logins, Telegram data, Apple Notes, keystrokes, screenshots, and session material. Notable infrastructure included zoom[.]uswe05[.]us, mylingocoin[.]com, supportzm[.]com, zmsupport[.]com, breakdream[.]com, dreamdie[.]com, cmailer[.]pro, and support-zoom[.]us, showing a focused data-harvesting operation for cryptocurrency theft and follow-on social engineering.

Indicators of Compromise

Type Value First Seen Last Seen
YARA G_Backdoor_WAVESHAPER_1 2026-02-10 2026-03-31
HASH c91725905b273e81e9cc6983a11c8d60 2026-02-10 2026-03-31
DOMAIN mylingocoin.com 2026-02-10 2026-03-02
DOMAIN zmsupport.com 2026-02-10 2026-03-02
DOMAIN dreamdie.com 2026-02-10 2026-03-02
DOMAIN breakdream.com 2026-02-10 2026-03-02
DOMAIN supportzm.com 2026-01-29 2026-03-02
YARA G_Datamine_CHROMEPUSH_1 2026-02-10 2026-02-10
YARA G_Datamine_DEEPBREATH_1 2026-02-10 2026-02-10
YARA G_APTFIN_Downloader_SUGARLOADER… 2026-02-10 2026-02-10
YARA G_APTFIN_Downloader_SUGARLOADER… 2026-02-10 2026-02-10
YARA G_Backdoor_SILENCELIFT_1 2026-02-10 2026-02-10
YARA G_Downloader_HYPERCALL_1 2026-02-10 2026-02-10
YARA G_Backdoor_WAVESHAPER_2 2026-02-10 2026-02-10
HASH 3712793d3847dd0962361aa528fa124c 2026-02-10 2026-02-10
HASH 4e4f2dfe143ba261fd8a18d1c4b58f2e 2026-02-10 2026-02-10
HASH eb7635f4836c9e0aa4c315b18b051cb5 2026-02-10 2026-02-10
URL http://mylingocoin.com/audio/fi… 2026-02-10 2026-02-10
URL http://cmailer.pro:80/upload 2026-02-10 2026-02-10
DOMAIN cmailer.pro 2026-02-10 2026-02-10

Related Actors

Related Reports

« Back