| SYMBOL | COMMON_NAME | aka. SYNONYMS |
CryptoCore is a North Korean APT known for targeting cryptocurrency exchanges and financial institutions, employing spear-phishing techniques that lead to LONEJOGGER malware infections. The group has leveraged social engineering tactics, including deepfake technology and hijacked YouTube accounts, to execute sophisticated giveaway scams that deceive victims into sending cryptocurrencies. Their operations have involved the misuse of platforms like Gemini for reconnaissance and the development of fraudulent content. Additionally, CryptoCore has been linked to a variety of campaigns, including Dangerous Password and SnatchCrypto, focusing on financial gain through cryptocurrency theft.
| 2026-07-24
⋅
Google
⋅
Updated Cyber Threat Actor Naming System APT15 APT20 APT27 APT28 APT29 APT30 APT31 APT33 APT35 APT37 APT39 APT40 APT41 APT42 APT45 APT5 BlackTech Callisto Conference Crew FIN11 FIN6 FIN7 FIN8 MuddyWater MUSTANG PANDA Naikon OilRig Sandworm TEMP.Hermit Tick Tonto Team Turla UAC-0020 UNC1069 UNC1088 UNC2814 |
| 2026-05-28
⋅
ESET Research
⋅
ESET APT Activity Report Q4 2025–Q1 2026 WAVESHAPER BirdCall BLINDINGCAN RokRAT Rook Tiger RAT |
| 2026-03-31
⋅
Google
⋅
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack WAVESHAPER |
| 2026-03-02
⋅
Moonlock
⋅
Fake VCs target crypto talent in a new ClickFix campaign AmodalTea |
| 2026-02-09
⋅
Mandiant
⋅
UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering SUGARLOADER WAVESHAPER |
| 2025-11-05
⋅
Google
⋅
GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools PromptLock UNC1069 |
| 2023-10-10
⋅
Mandiant
⋅
Assessed Cyber Structure and Alignments of North Korea in 2023 TraderTraitor UNC1069 |