Google links axios supply chain attack to North Korean group

2026-04-01T08:51:57Zfebb7bb531b1291526899c4ade9ac58d50f1a3c74b1622eb1dbdadf5d00bd64e
AxiosCISACitrix NetScalerLeak BazaarNorth KoreaSentinelOneUNC1069UkraineUranium Financecriticalcryptocurrency-theftdata-monetizationindictmentmacOS malwarephishingpro-Russianransomwaresmart-contract-exploitsupply-chainvulnerability

What happened

A series of security incidents and advisories: Google and other researchers attribute an Axios supply-chain compromise to North Korean group UNC1069 (SentinelOne links macOS malware to the actor). The U.S. indicted a Maryland man for a 2021 smart-contract theft of $54M from Uranium Finance. A new criminal service called “Leak Bazaar” aims to monetize data stolen by ransomware operators. CISA ordered federal agencies to urgently patch a critical Citrix NetScaler vulnerability (CVSS 9.3). Separately, a pro‑Russian group has impersonated Ukraine’s national cyber agency in phishing campaigns. The報

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
febb7bb531b1291526899c4ade9ac58d50f1a3c74b1622eb1dbdadf5d00bd64e
Enrichment time
2026-04-01T08:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.