Google Cloud flags North Korea crypto malware
Mandiant, which operates under Google Cloud, has identified an escalating North Korea-linked cyber campaign targeting cryptocurrency and fintech firms with advanced malware and AI-enabled social engineering.
The threat cluster, tracked as UNC1069, deployed seven distinct malware families designed to harvest and exfiltrate sensitive data, marking a significant expansion of activity first monitored by Mandiant in 2018.
“This investigation revealed a tailored intrusion resulting in the deployment of seven unique malware families, including a new set of tooling designed to capture host and victim data: SILENCELIFT, DEEPBREATH and CHROMEPUSH,”
Mandiant said in its report.
The campaign leveraged compromised Telegram accounts and staged fake Zoom meetings featuring AI-generated deepfake videos, with victims tricked into running hidden commands in so-called ClickFix attacks.
Two newly identified malware strains, CHROMEPUSH and DEEPBREATH, were engineered to bypass key operating system protections and extract personal data, and following the announcement the Alphabet share price was unchanged at $XX.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
White House Pressure Fails to Prevent Hawkish Shift! Federal Reserve Rate Hike Looms, Waller-Trump Relationship Faces Major Test
The Federal Reserve is expected to raise interest rates by 25 basis points on Wednesday, marking the first increase since 2023; the market is pricing in a probability of over 90%, and the relationship between the White House and Walsh faces a test.

Firm Belief in Fed Rate Hike Tonight! US Bond Market Shows "Extreme Short Positions"
Japanese Yen flatlines ahead of Fed rate decicion
Kamino names Michael Weisz CEO as its RWA push shifts to credit
