Live
eineurope/
Home/Uncategorized/Topic · 🎭 North Korean UNC1069 Targets Crypto Sector via Fake VC Me
Uncategorized21 Apr

🎭 North Korean UNC1069 Targets Crypto Sector via Fake VC Meetings North Korean...

🎭 North Korean UNC1069 Targets Crypto Sector via Fake VC Meetings North Korean threat actor UNC1069, overlapping with .

Sources
1 verified
Location
Updated
Tuesday, 21 April 2026 at 11:03 UTC
No media · text-only dispatch
Synthesis · 1 sources
🎭 North Korean UNC1069 Targets Crypto Sector via Fake VC Meetings North Korean threat actor UNC1069, overlapping with Bluenoroff, is conducting social engineering campaigns against cryptocurrency and Web3 professionals. Attackers create fabricated venture capital firms like "WallEye Capital" and use compromised LinkedIn/Telegram accounts to arrange meetings. Victims are redirected to fake conferencing platforms hosting ClickFix payloads that deploy customized RATs—CageyChameleon for Windows, NukeSped for macOS, and Cabbage RAT for Linux—designed to exfiltrate crypto wallets and system data. The campaign demonstrates advanced cross-platform capability and infrastructure mimicry, according to Google Cloud and Mandiant. 🛰️ Open sources - closed narratives @sitreports
e/eineurope · topic · T-02917