- Mandiant reports UNC1069 with compromised Telegram, fake Zoom calls, and deepfake videos
- Victims are tricked into installing malware suites including WAVESHAPER, HYPERCALL, and SUGARLOADER
- North Korean attackers continue state-linked theft campaign targeting crypto companies including Lazarus and TraderTraitor
North Korean cybercriminals appear to be stepping up their strategy, with a new Mandiant report claiming hackers are using a combination of compromised Telegram accounts, fake Zoom calls, deepfake videos, and six different malware strains.
This sinister concoction appears to have been used against organizations in the cryptocurrency space with the purpose of stealing cryptocurrency stacks.
Mandiant said in its report that it used this advanced technology to observe a group tracked as UNC1069. The attack begins with a compromised Telegram account of a CEO or similar executive. This account is then used to start a conversation with the victim, and after some interaction, they are invited to join a Zoom call.
attack failure
However, this call is not legitimate. This is a spoofed Zoom meeting hosted on the threat actor’s infrastructure (Zoom).[.]uswe05[.]us. On the phone, the victim is shown a deepfake video impersonating the CEO and claiming that the victim’s audio is not working and needs to be fixed.
Finally, instead of “fixing” non-existent errors in the traditional ClickFix fashion, victims are presented with a solution that deploys the entire malware, including WAVESHAPER, HYPERCALL, HIDENCALL, SUGARLOADER, SILENCELIFT, DEEPBREATH, and CHROMEPUSH.
These tools work together to form a multi-step infection chain that enables persistence, credential harvesting, browser data theft, and long-term access.
UNC1069 is not a widely recognized threat actor. However, since UNC stands for Uncategorized (or Unclassified), it could mean that a previously observed threat actor has changed its infrastructure or technology and is not yet properly attributed.
North Korean attackers are notorious for targeting crypto businesses. Some of the biggest heists have been attributed to state-backed groups such as Lazarus, which are often tasked with stealing cryptocurrencies that fund national weapons programs and state institutions.
The largest cryptocurrency heist ever recorded occurred on February 21, 2025, when Dubai-based exchange Bybit was hacked, with approximately 1.5 billion Ether-related assets stolen from cold wallets. Analysts and law enforcement have linked this attack to North Korean state-linked cybercrime groups such as Lazarus Group and TraderTraitor.

The best antivirus tool for every budget
Follow TechRadar on Google News and Add us as a preferred source Get expert news, reviews, and opinions in your feed. Be sure to click the follow button!
Of course you can also do Follow TechRadar on TikTok Check out news, reviews, and unboxings in video format and stay updated regularly. whatsapp Too.
