Mandiant, a US cybersecurity firm owned by Google Cloud, has discovered that a North Korean-linked threat group is ramping up its social engineering attacks against cryptocurrency and fintech companies. The group (codenamed UNC1069) has deployed seven malware suites, including the newly discovered SILENCELIFT, DEEPBREATH, and CHROMEPUSH, designed to acquire sensitive data and steal digital assets. Attackers are using compromised Telegram accounts and AI-generated deepfake videos to lure victims into fake Zoom meetings. Mandiant has been tracking the group since 2018, but advancements in AI have helped it scale its malicious activity since November 2025. In one intrusion incident, attackers used a stolen cryptocurrency founder's Telegram account to initiate contact, using a so-called ClickFix attack to trick victims into executing "troubleshooting" instructions containing hidden commands. (Cointelegraph)