North Korea–linked hackers drain $285M from Drift in sophisticated attack
2026-04-03T20:51:51Z•e74ecf52bfd96a88ce1c51c676f99983755a59e803b552ed5c4d27595d72a354
AGEWHEEZEAxiosCERT-UA impersonationCVE-2026-20093CVE-2026-5281Chrome zero-dayCisco patchesCrystalX RATHasbroNorth KoreaPSK WindUAC-0255UNC1069WebGPU Dawncryptocurrency heistdata breachfake appmalware-as-a-servicenpmphishingspywarespyware vendorstealersupply chain compromise
What happened
Multiple high-impact cyber incidents and vulnerabilities reported: a sophisticated North Korea-linked campaign reportedly drained $285M from crypto firm Drift using durable nonce/pre-signed transaction tricks; Google attributed the Axios npm supply-chain compromise to North Korean APT UNC1069; Google patched an actively exploited Chrome/WebGPU zero-day (CVE-2026-5281) which CISA added to its KEV catalog; Cisco released fixes including critical issues (notably CVE-2026-20093); Kaspersky uncovered CrystalX RAT offered as MaaS with spyware/stealer/RAT features; pro‑Iran Handala group claimed a侵攻/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- e74ecf52bfd96a88ce1c51c676f99983755a59e803b552ed5c4d27595d72a354
- Enrichment time
- 2026-04-03T20:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.