North KoreaWidely attributedUnknown

UNC1069

North Korean threat actor also tracked as CryptoCore, MASAN, Dangerous Password, and Leery Turtle. Specialises in cryptocurrency exchange targeting using spear-phishing, AI-generated deepfakes, and ClickFix social engineering.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
8.8
Moderate signal strength
Mentions11
Sources1
High conf.9
Last seenJun 2026
First observed
Last active
Origin
North Korea
Aliases
5
Techniques
0
Campaigns
0
North Korea
TargetsCryptocurrencyFinancial
RegionsGlobal

Attribution signals

11 mentions · 1 source
#1attributed tohigh
Unspecified
mandiant
May 2026

"attributed to UNC1069, a financially motivated threat actor active since at least 2018"

#2attributed tohigh
Unspecified
huntress
Jun 2026

"Google Threat Intelligence Group has also attributed the attack to UNC1069, a suspected North Korean threat actor"

#3known to usehigh
TTP match
mandiant
May 2026

"UNC1069 is known to use tools like Gemini to develop tooling, conduct operational research, and assist during the reconnaissance stages"

#4attributeshigh
MalwareInfrastructure
mandiant
May 2026

"GTIG attributes this activity to UNC1069, a financially motivated North Korea-nexus threat actor active since at least 2018, based on the use of WAVESHAPER.V2, an updated version of WAVESHAPER previously used by this threat actor."

#5attributeshigh
Infrastructure
mandiant
May 2026

"GTIG attributes this activity to UNC1069, a financially motivated North Korea-nexus threat actor active since 2018."

#6revealed connectionshigh
Infrastructure
mandiant
May 2026

"Analysis of the C2 infrastructure (sfrclak[.]com resolving to 142.11.206.73) revealed connections from a specific AstrillVPN node previously used by UNC1069. Additionally, adjacent infrastructure hosted on the same ASN has been historically linked to UNC1069 operation"

#7attributinghigh
InfrastructureGeopolitical
huntress
Jun 2026

"Various researchers have pointed to links in the attack to DPRK infrastructure, with Google attributing the incident specifically to UNC1069, a financially motivated North Korean threat actor active since at least 2018."

#8identifiedhigh
TTP match
mandiant
May 2026

"identified UNC1069's transition from using AI for simple productivity gains to deploying novel AI-enabled lures in active operations"

#9observedhigh
VictimologyTTP match
mandiant
May 2026

"Mandiant has observed UNC1069 employing these techniques to target both corporate entities and individuals within the cryptocurrency industry"

#10shows overlapsmoderate
Infrastructure
mandiant
May 2026

"Analysis of infrastructure artifacts used in this attack shows overlaps with infrastructure used by UNC1069 in past activities"

#11shares techniques withmoderate
TTP match
infosecurity-magazine
Jun 2026

"the actor shares techniques with North Korean groups such as UNC1069, also known as Sleet"

Hedge terms observed

attributed toattributesattributingidentifiedknown to useobservedrevealed connectionsshares techniques withshows overlaps