{"id":711382,"date":"2026-02-11T15:45:12","date_gmt":"2026-02-11T12:45:12","guid":{"rendered":"https:\/\/buradabiliyorum.com\/en\/google-cloud-flags-north-korea-linked-crypto-malware-campaign\/"},"modified":"2026-02-11T15:45:12","modified_gmt":"2026-02-11T12:45:12","slug":"google-cloud-flags-north-korea-linked-crypto-malware-campaign","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/google-cloud-flags-north-korea-linked-crypto-malware-campaign\/","title":{"rendered":"Google Cloud flags North Korea-linked crypto malware campaign"},"content":{"rendered":"<p style=\"float:right;margin:0 0 10px 15px;width:240px\"><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjUtMDcvMDE5N2M0YzEtOGY0NS03YjNjLThmNWItNDZjZjEyZTdlOThh.jpg\" alt=\"Google Cloud flags North Korea-linked crypto malware campaign\" class=\"type:primaryImage\"><\/p>\n<p>Mandiant, which operates under Google Cloud, has tracked the suspected North Korean scammers since 2018, but AI has helped scale up malicious attacks since November 2025.<\/p>\n<p>North Korea-linked threat actors are escalating <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">social<\/a> engineering campaigns targeting cryptocurrency and fintech companies, deploying new malware designed to harvest sensitive data and steal digital assets.<\/p>\n<p>In a recent campaign, a threat cluster tracked as UNC1069 deployed seven malware families aimed at capturing and exfiltrating victim data, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/unc1069-targets-cryptocurrency-ai-social-engineering\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/unc1069-targets-cryptocurrency-ai-social-engineering\">according<\/a> to a Tuesday report by Mandiant, a US cybersecurity firm Mandiant which operates under Google Cloud.<\/p>\n<p>The campaign relied on social engineering schemes involving compromised Telegram accounts and fake Zoom meetings with deepfake videos generated through artificial intelligence tools.<\/p>\n<p>Read more<\/p>\n<\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMN63nwsw68G3Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/buradabiliyorum.com\/en\/category\/general\/\" target=\"_blank\" >General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/north-korean-hackers-malware-crypto-fintech-social-engineering?utm_source=rss_feed&#038;utm_medium=feed&#038;utm_campaign=rss_partner_inbound\" target=\"_blank\" >Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mandiant, which operates under Google Cloud, has tracked the suspected North Korean scammers since 2018, but AI has helped scale up malicious attacks since November 2025. North Korea-linked threat actors are escalating social engineering campaigns targeting cryptocurrency and fintech companies, deploying new malware designed to harvest sensitive data and steal digital assets. In a recent&#8230;<\/p>\n","protected":false},"author":1,"featured_media":711383,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/f=auto,onerror=redirect,w=1200\/https:\/\/s3.cointelegraph.com\/uploads\/2025-07\/0197c4c1-8f45-7b3c-8f5b-46cf12e7e98a","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-711382","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/711382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=711382"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/711382\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/711383"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=711382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=711382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=711382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}