North Korea–linked hackers drain $285M from Drift in sophisticated attack

2026-04-03T20:51:51Ze74ecf52bfd96a88ce1c51c676f99983755a59e803b552ed5c4d27595d72a354
AGEWHEEZEAxiosCERT-UA impersonationCVE-2026-20093CVE-2026-5281Chrome zero-dayCisco patchesCrystalX RATHasbroNorth KoreaPSK WindUAC-0255UNC1069WebGPU Dawncryptocurrency heistdata breachfake appmalware-as-a-servicenpmphishingspywarespyware vendorstealersupply chain compromise

What happened

Multiple high-impact cyber incidents and vulnerabilities reported: a sophisticated North Korea-linked campaign reportedly drained $285M from crypto firm Drift using durable nonce/pre-signed transaction tricks; Google attributed the Axios npm supply-chain compromise to North Korean APT UNC1069; Google patched an actively exploited Chrome/WebGPU zero-day (CVE-2026-5281) which CISA added to its KEV catalog; Cisco released fixes including critical issues (notably CVE-2026-20093); Kaspersky uncovered CrystalX RAT offered as MaaS with spyware/stealer/RAT features; pro‑Iran Handala group claimed a侵攻/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
e74ecf52bfd96a88ce1c51c676f99983755a59e803b552ed5c4d27595d72a354
Enrichment time
2026-04-03T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · North Korea–linked hackers drain $285M from Drift in sophisticated attack · Baitaphish