UNC1069 is a North Korean APT group known for targeting cryptocurrency exchanges with LONEJOGGER malware and crypto scams.
Analyst brief
CryptoCore (UNC1069, MASAN, MIDNIGHT NEPTUNE) is a North Korean APT group primarily targeting cryptocurrency exchanges and financial institutions. The group uses spear-phishing emails to deliver the LONEJOGGER malware and employs social engineering tactics, including deepfake technology and hijacked YouTube accounts, to conduct fraudulent crypto giveaway scams. They have historically run campaigns like "Dangerous Password" and "SnatchCrypto" for financial gain and have abused legitimate platforms like Gemini for reconnaissance. Defenders should focus on user awareness against targeted spear-phishing and crypto scam attempts, and strengthen endpoint monitoring for LONEJOGGER indicators of compromise.
UNC1069
MASANCryptoCoreMIDNIGHT NEPTUNE
unknown
CryptoCore is a North Korean APT known for targeting cryptocurrency exchanges and financial institutions, employing spear-phishing techniques that lead to LONEJOGGER malware infections. The group has leveraged social engineering tactics, including deepfake technology and hijacked YouTube accounts, to execute sophisticated giveaway scams that deceive victims into sending cryptocurrencies. Their operations have involved the misuse of platforms like Gemini for reconnaissance and the development of fraudulent content. Additionally, CryptoCore has been linked to a variety of campaigns, including Dangerous Password and SnatchCrypto, focusing on financial gain through cryptocurrency theft.