UNC1069
Aliases: MASAN, CryptoCore
- First seen
- 2018-01-01 00:00:00
- Origin
- KP
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-07-21 08:33:45
- Profile updated
- 2026-07-07 12:07:31
Targeted industries: financial-services technology-and-telecommunications
Context
CryptoCore is a North Korean APT known for targeting cryptocurrency exchanges and financial institutions, employing spear-phishing techniques that lead to LONEJOGGER malware infections. The group has leveraged social engineering tactics, including deepfake technology and hijacked YouTube accounts, to execute sophisticated giveaway scams that deceive victims into sending cryptocurrencies. Their operations have involved the misuse of platforms like Gemini for reconnaissance and the development of fraudulent content. Additionally, CryptoCore has been linked to a variety of campaigns, including Dangerous Password and SnatchCrypto, focusing on financial gain through cryptocurrency theft.
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- Mandiant — North Korea Cyber Structure Alignment 2023 (report)
- spixnet.com — Newly Exposed Apt43 Hacking Group Targeting Us Orgs Since 2018 (report)
- cloud.google.com — Threat Actor Usage Of Ai Tools (report)