ChainCatcher reports that, according to Cointelegraph, the U.S. cybersecurity firm Mandiant, a subsidiary of Google Cloud, has discovered that North Korea-linked threat groups are increasing social engineering attacks targeting cryptocurrency and fintech companies.
The threat group (codenamed UNC1069) has deployed seven malicious software suites, including newly discovered SILENCELIFT, DEEPBREATH, and CHROMEPUSH, aimed at obtaining sensitive data and stealing digital assets. The attackers exploit compromised Telegram accounts and use AI-generated deepfake videos to lure victims into fake Zoom meetings. Mandiant has been tracking this group since 2018, but advances in AI have helped the group expand its malicious activities since November 2025. In one intrusion, the attackers used stolen cryptocurrency founder Telegram accounts to initiate contact and employed a so-called ClickFix attack to trick victims into executing “troubleshooting” commands containing hidden instructions.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Related Articles
ICBC issues OpenClaw risk warning, financial institutions remain cautious about AI proxy tools
Financial institutions are cautious about AI proxy tools like OpenClaw, concerned about data leaks and system risks. Industrial and Commercial Bank of China issued a risk warning, advising users to authorize cautiously, not to believe in high-yield promises easily, and to protect personal information.
GateNews8m ago
Cryptocurrency project Aethir spreads negative news, with the marketing director accused of having sought women for Epstein.
Gate News reports that on March 10, the crypto community announced that Aethir's marketing director Masha Prusso was accused of having sourced women for Epstein. Meanwhile, community insiders revealed that Aethir has recently undergone large-scale layoffs, with several co-founders and executives leaving one after another, suspected of soft Rug pulling. It is also reported that Masha Prusso's personal website has been taken down recently.
GateNews53m ago
South Korean prosecutors sell stolen and recovered Bitcoin 320.8 coins, cash out $21.5 million, and remit to the national treasury
Gate News: On March 10, the Gwangju District Prosecutor's Office in South Korea sold 320.8 Bitcoins, with the proceeds of 31.6 billion Korean Won (approximately $21.5 million) remitted to the national treasury. The Bitcoins were originally confiscated after a crackdown on an illegal gambling platform, stolen in August 2025 due to a phishing attack on an official, and voluntarily returned by the hacker in February this year. The prosecution then sold the assets in batches over 11 days (from February 24 to March 6). The hacker remains at large, and the investigation is ongoing. (The Block)
GateNews1h ago
JELLYJELLY Contract and Spot Price Discrepancy at 34%, Manipulation Warning Alert Triggered
JELLYJELLY tokens experienced an extreme divergence of 34% between the perpetual contract mark price and the on-chain spot price on March 10, suspected of price manipulation. Analysis shows a surge in open interest and a funding rate reaching -2% every 4 hours, indicating market instability and manipulation risk. Analysts warn investors that this situation could trigger significant price volatility and reflects structural risks during the integration process of decentralized and centralized exchanges.
MarketWhisper3h ago
Compound official website hacked again: Phishing site disguises attack on DeFi lending platform, raising security concerns
DeFi lending protocol Compound Finance recently experienced a security incident, with users reporting that its official website was redirected to a phishing page. Attackers used domain spoofing to carry out the attack. Although no funds were lost, this is the second similar incident Compound has faced in the past two years. Security experts stated that the automation of phishing tools increases the risk of attacks. The ongoing issues facing Compound are undermining market confidence, and front-end security and governance transparency are becoming key factors for its long-term development.
GateNews4h ago
Beware of crypto scams: Political organizations report impersonators soliciting Bitcoin and Ethereum donations related to Iran issues
The Russian "All-Russian People's Front" warns that scammers are forging donation documents to induce supporters of Iran to donate cryptocurrencies, claiming that the funds will be used to aid Ukrainian soldiers. The organization reiterates that all crypto fundraising activities in its name are scams, and legitimate donations can only be made through official website bank transfers. Meanwhile, Russian security agencies are stepping up efforts to combat related criminal activities. Cryptocurrencies are becoming increasingly important in the political and military funding flows in the Middle East, posing new security challenges for users.
GateNews4h ago