Google links axios supply chain attack to North Korean group

2026-04-01T02:51:54Z878439cdbcd5ecf4776da4180cb0158a0f2a4514a4380c5be4e110c46367b4d1
AxiosCISACitrix NetScalerGoogle Threat IntelligenceLeak BazaarNorth KoreaSentinelOneUNC1069Uranium Financecritical-vulnerabilitycrypto-theftdata-monetizationgovernment-targetingimpersonationindictmentmacOS-malwarephishingpro-Russian-actorsransomwaresmart-contract-hacksupply-chain

What happened

Multiple high-impact cyber incidents and developments: Google Threat Intelligence and other researchers attribute an Axios supply-chain compromise to a North Korean actor tracked as UNC1069; SentinelOne links the group to macOS-focused malware dating to 2023. U.S. prosecutors indicted a Maryland man (Spalletta) for exploiting smart-contract flaws to steal ~$54M from the Uranium Finance platform in 2021. A new criminal service, “Leak Bazaar,” aims to monetize data stolen by ransomware groups. CISA ordered federal agencies to urgently patch a critical Citrix NetScaler vulnerability (rated 9.3/10

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
878439cdbcd5ecf4776da4180cb0158a0f2a4514a4380c5be4e110c46367b4d1
Enrichment time
2026-04-01T02:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.