North KoreaWidely attributedUnknown

UNC1069

North Korean threat actor also tracked as CryptoCore, MASAN, Dangerous Password, and Leery Turtle. Specialises in cryptocurrency exchange targeting using spear-phishing, AI-generated deepfakes, and ClickFix social engineering.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
6.4
Moderate signal strength
Mentions8
Sources1
High conf.7
Last seenMay 2026
First observed
Last active
Origin
North Korea
Aliases
5
Techniques
0
Campaigns
0
North Korea
TargetsCryptocurrencyFinancial
RegionsGlobal

Attribution signals

8 mentions · 1 source
#1attributed tohigh
Unspecified
mandiant
May 2026

"attributed to UNC1069, a financially motivated threat actor active since at least 2018"

#2observedhigh
VictimologyTTP match
mandiant
May 2026

"Mandiant has observed UNC1069 employing these techniques to target both corporate entities and individuals within the cryptocurrency industry"

#3known to usehigh
TTP match
mandiant
May 2026

"UNC1069 is known to use tools like Gemini to develop tooling, conduct operational research, and assist during the reconnaissance stages"

#4attributeshigh
MalwareInfrastructure
mandiant
May 2026

"GTIG attributes this activity to UNC1069, a financially motivated North Korea-nexus threat actor active since at least 2018, based on the use of WAVESHAPER.V2, an updated version of WAVESHAPER previously used by this threat actor."

#5attributeshigh
Infrastructure
mandiant
May 2026

"GTIG attributes this activity to UNC1069, a financially motivated North Korea-nexus threat actor active since 2018."

#6revealed connectionshigh
Infrastructure
mandiant
May 2026

"Analysis of the C2 infrastructure (sfrclak[.]com resolving to 142.11.206.73) revealed connections from a specific AstrillVPN node previously used by UNC1069. Additionally, adjacent infrastructure hosted on the same ASN has been historically linked to UNC1069 operation"

#7identifiedhigh
TTP match
mandiant
May 2026

"identified UNC1069's transition from using AI for simple productivity gains to deploying novel AI-enabled lures in active operations"

#8shows overlapsmoderate
Infrastructure
mandiant
May 2026

"Analysis of infrastructure artifacts used in this attack shows overlaps with infrastructure used by UNC1069 in past activities"

Hedge terms observed

attributed toattributesidentifiedknown to useobservedrevealed connectionsshows overlaps