Google links axios supply chain attack to North Korean group
2026-04-01T08:51:57Z•febb7bb531b1291526899c4ade9ac58d50f1a3c74b1622eb1dbdadf5d00bd64e
AxiosCISACitrix NetScalerLeak BazaarNorth KoreaSentinelOneUNC1069UkraineUranium Financecriticalcryptocurrency-theftdata-monetizationindictmentmacOS malwarephishingpro-Russianransomwaresmart-contract-exploitsupply-chainvulnerability
What happened
A series of security incidents and advisories: Google and other researchers attribute an Axios supply-chain compromise to North Korean group UNC1069 (SentinelOne links macOS malware to the actor). The U.S. indicted a Maryland man for a 2021 smart-contract theft of $54M from Uranium Finance. A new criminal service called “Leak Bazaar” aims to monetize data stolen by ransomware operators. CISA ordered federal agencies to urgently patch a critical Citrix NetScaler vulnerability (CVSS 9.3). Separately, a pro‑Russian group has impersonated Ukraine’s national cyber agency in phishing campaigns. The報
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- febb7bb531b1291526899c4ade9ac58d50f1a3c74b1622eb1dbdadf5d00bd64e
- Enrichment time
- 2026-04-01T08:51:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.