Google links axios supply chain attack to North Korean group
2026-03-31T20:51:57Z•058ea9f2da76f5d5a481a0fe32b1f04a1e2ab81e54c637041561f13e63df388d
UNC1069axioscisacitrix-netscalercritical-vulnerabilitycryptocurrency-theftcvss-9.3data-monetizationleak-bazaarmacos-malwarenorth-koreaphishingpro-russian-actorsransomwaresentinelonesmart-contract-hacksupply-chain-attackukraine-impersonationuranium-finance
What happened
Multiple active threats and incidents: Google GTIG and other researchers attribute the Axios supply‑chain attack to North Korean actor UNC1069 (SentinelOne notes related macOS malware activity since 2023). CISA urged federal agencies to urgently patch a Citrix NetScaler vulnerability rated CVSS 9.3. A new criminal service called “Leak Bazaar” aims to monetize data stolen by ransomware groups. Separately, U.S. prosecutors indicted a Maryland man for a 2021 smart‑contract theft from Uranium Finance, and pro‑Russian actors have been impersonating Ukraine’s national cyber agency in phishing ops.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 058ea9f2da76f5d5a481a0fe32b1f04a1e2ab81e54c637041561f13e63df388d
- Enrichment time
- 2026-03-31T20:51:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.