A North Korea–nexus threat actor is enhancing its social engineering playbook. The group is integrating AI-enabled lures into crypto-focused hacks, according to a new report from Google’s Mandiant team.
The operation reflects a continued evolution in state-linked cyber activity targeting the digital asset sector, which saw a notable increase in 2025.
Sponsored
Sponsored
Fake Zoom Call Triggers Malware Attack on Crypto Firm
In its latest report, Mandiant detailed its investigation into an intrusion targeting a FinTech company in the cryptocurrency sector. The attack was attributed to UNC1069. It is a financially motivated threat group active since at least 2018, with links to North Korea.
“Mandiant has observed this threat…







