Activity timeline
UNC1069 appears in 18 tracked threats between and ; the busiest month was 2026-04 with 5 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 17 of 18 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 13 of 18 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 11 of 18 tracked threats
- T1195 Supply Chain Compromise — Initial Accessobserved in 11 of 18 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 9 of 18 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 9 of 18 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 9 of 18 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 9 of 18 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 9 of 18 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 9 of 18 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 9 of 18 tracked threats
- T1059.001 PowerShell — Executionobserved in 8 of 18 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 8 of 18 tracked threats
- T1195.001 Compromise Software Dependencies and Development Tools — Initial Accessobserved in 8 of 18 tracked threats
- T1571 Non-Standard Port — Command and Controlobserved in 8 of 18 tracked threats
Tracked threats
- Evolution of Web3 in Cloud Supply Chain Attacks: Blockchain Smart-Contract C2 (EtherHiding, TxDataHiding, NullReceiver) in DPRK-Linked npm/Go/Packagist/Rust CampaignsHIGH
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)HIGH
- Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform infostealer backdoor at compile timeCRITICAL
- Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked BackdoorCRITICAL
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via proc-macro1 Typosquat (DPRK/Sapphire Sleet)CRITICAL
- Popular Rust Packages With 244M Downloads Compromised in Supply Chain AttackCRITICAL
- NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packagesHIGH
- Sapphire Sleet (DPRK) 'easy-day-js' Supply-Chain Compromise of 140+ Mastra npm Packages via Hijacked Maintainer AccountCRITICAL
- North Korean Threat Actors Weaponize Developer Tools (VS Code, npm, GitHub) for Cross-Platform Malware Delivery — Contagious Interview / UNK_DeadDropHIGH
- Axios npm Supply Chain Compromise — Malicious axios@1.14.1 and axios@0.30.4 Inject plain-crypto-js@4.2.1 RAT DropperCRITICAL
- Axios npm Supply Chain Compromise (v1.14.1 / v0.30.4) Reaches OpenAI macOS Signing Pipeline, Forces Apple Certificate Rotation — DPRK UNC1069 / Sapphire Sleet WAVESHAPER.V2CRITICAL
- Axios npm Supply Chain Compromise — WAVESHAPER.V2 Cross-Platform RAT Deployment by UNC1069/Sapphire Sleet (DPRK)CRITICAL
- Axios npm Supply Chain Compromise by Sapphire Sleet (DPRK) — Cross-Platform RAT via Phantom DependencyCRITICAL
- UNC1069 Compromises Axios NPM Package in Supply Chain Attack Deploying WAVESHAPER.V2 Cross-Platform BackdoorCRITICAL
- North Korea (UNC1069) Supply Chain Compromise of Axios NPM Package via Backdoored plain-crypto-js DependencyCRITICAL
- Axios NPM Supply Chain Compromise — Cross-Platform RAT via Malicious Transitive Dependency (plain-crypto-js)CRITICAL
- Axios npm Supply Chain Attack: Cross-Platform RAT Delivery via Compromised Maintainer Credentials (GHSA-fw8c-xr5c-95f9)CRITICAL
- Axios npm Supply Chain Attack via Malicious plain-crypto-js Dependency (Cross-Platform RAT Dropper)CRITICAL