UNC1069

Aliases: MASAN, CryptoCore

First seen
2018-01-01 00:00:00
Origin
KP
Primary motivation
financial-gain
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-21 08:33:45
Profile updated
2026-07-07 12:07:31

Targeted industries: financial-services technology-and-telecommunications

Context

CryptoCore is a North Korean APT known for targeting cryptocurrency exchanges and financial institutions, employing spear-phishing techniques that lead to LONEJOGGER malware infections. The group has leveraged social engineering tactics, including deepfake technology and hijacked YouTube accounts, to execute sophisticated giveaway scams that deceive victims into sending cryptocurrencies. Their operations have involved the misuse of platforms like Gemini for reconnaissance and the development of fraudulent content. Additionally, CryptoCore has been linked to a variety of campaigns, including Dangerous Password and SnatchCrypto, focusing on financial gain through cryptocurrency theft.

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • Mandiant — North Korea Cyber Structure Alignment 2023 (report)
  • spixnet.com — Newly Exposed Apt43 Hacking Group Targeting Us Orgs Since 2018 (report)
  • cloud.google.com — Threat Actor Usage Of Ai Tools (report)

External references