Close Menu
fintechbits
  • News
  • AI
  • Acquisitions
  • Trends
  • Insights
  • Rumors
  • Startups
  • finjobsly

Subscribe to Updates

Get the latest news from Fintechbits.

Trending Now

Basware Acquires Redmap to Enhance AI-Powered Accounts Payable in Australia

December 21, 2025

Is an AI Advisor a Companion or a Financial Hazard?

December 21, 2025

How data, artificial intelligence, and regulations are transforming the future of global fintech

December 21, 2025

Struggling to establish your financial goals for 2026? AI tools like ChatGPT and Google Gemini provide innovative strategies to help you plan for the future. Discover ways to utilize them effectively.

December 20, 2025
Facebook X (Twitter) Instagram
Trending
  • Basware Acquires Redmap to Enhance AI-Powered Accounts Payable in Australia
  • Is an AI Advisor a Companion or a Financial Hazard?
  • How data, artificial intelligence, and regulations are transforming the future of global fintech
  • Struggling to establish your financial goals for 2026? AI tools like ChatGPT and Google Gemini provide innovative strategies to help you plan for the future. Discover ways to utilize them effectively.
  • The potential and constraints of AI in personal finance
  • Struggling to define your financial objectives for 2026? Seek help from AI.
  • How Artificial Intelligence is Transforming Corporate Finance
  • What is the effect of the XRP trading exodus on Asian fintech startups?
Facebook X (Twitter) Instagram Pinterest Vimeo
fintechbits
  • News

    PayPal joins other fintech companies benefiting from Trump-era deregulation.

    December 16, 2025

    Zilch, the fintech unicorn, secures payment license from city regulator.

    December 10, 2025

    MobileMoney Fintech Reorganizes; Shareholders Endorse Merger and Waiver at Extraordinary General Meeting

    December 1, 2025

    Axis CRE Fund and Tishman Speyer launch Chennai FinTech City

    November 28, 2025

    Commemorating outside the office: Fintech firm treats employees to a getaway in Thailand

    November 11, 2025
  • AI

    Basware Acquires Redmap to Enhance AI-Powered Accounts Payable in Australia

    December 21, 2025

    Is an AI Advisor a Companion or a Financial Hazard?

    December 21, 2025

    Struggling to establish your financial goals for 2026? AI tools like ChatGPT and Google Gemini provide innovative strategies to help you plan for the future. Discover ways to utilize them effectively.

    December 20, 2025

    The potential and constraints of AI in personal finance

    December 20, 2025

    Struggling to define your financial objectives for 2026? Seek help from AI.

    December 20, 2025
  • Acquisitions

    Teybridge Capital Europe finalizes strategic purchase of London-based fintech company Atom CTO

    November 18, 2025

    Highlights from Santa Cruz County business: local fintech firm’s recent acquisition; startup showcases a surf helmet on Shark Tank

    November 12, 2025

    Ripple Becomes a Comprehensive Fintech Hub Following Hidden Road Acquisition, Reports TradingView News

    November 11, 2025

    Amazon concludes its acquisition of the Indian lender Axio, expanding its fintech efforts.

    September 11, 2025

    The incident involving the Kaustubh Kulkarni movement in Moomoo

    September 3, 2025
  • Trends

    Swiss Fintech Market 2025 – Key Regions and Recent Updates

    December 15, 2025

    Key Payment Trends in India

    December 15, 2025

    Emerging Trends in Fintech: Insights from SVB

    December 12, 2025

    Deloitte CEO calls on regulators to find a middle ground between fostering innovation and ensuring stability in the Fintech sector.

    December 12, 2025

    Deloitte Leader Calls for Regulators to Find a Balance Between Innovation and Stability in Fintech

    December 11, 2025
  • Insights

    MobileMoney Ltd recognizes leading FinTech partners and industry figures at the 2025 FinTech Stakeholder Dinner and Awards.

    December 11, 2025

    MobileMoney Fintech undergoes restructuring as shareholders consent to merger and waiver during EGM

    December 2, 2025

    Youth Driving Innovative Fintech Concepts as Digital Adoption Reaches 87%, According to FM Sitharaman

    November 13, 2025

    Propel Launches $10 Million Fund to Support Food Stamp Recipients Affected by Government Shutdown

    October 30, 2025

    The Fintechs Dominating LinkedIn’s Top Startups 2025 List in London

    October 29, 2025
  • Rumors

    Examination of Reality at $0.23 as GCV Excitement is Exposed as False

    December 15, 2025

    This week’s rumors focus on major breweries, robotics, and multi-million dollar auctions.

    November 22, 2025

    Speculations about Ubisoft acquisition following profit announcement delay

    November 18, 2025

    Bill Holdings’ Stock Price Jumps Despite Sell Rumors

    November 12, 2025

    Ripple clarifies there is no planned timeline for an IPO following the $500 million funding round.

    November 12, 2025
  • Startups

    What is the effect of the XRP trading exodus on Asian fintech startups?

    December 19, 2025

    KB Financial Hosts Demo Day for Fintech Lab to Foster Startup Growth

    December 15, 2025

    Leading Fintech Investors in Italy for 2025 – Fintech Schweiz Digital Finance News

    December 15, 2025

    Fintech Startup Mesa Closes Owner Card Rewards Initiative

    December 15, 2025

    ChosunbizFSC Organizes Korea Fintech Week 2025, Highlighting AI-Powered Personalization and Funding for Startups

    December 14, 2025
  • finjobsly
fintechbits
Home » North Korean hackers target Brazilian fintech with sophisticated phishing tactics
Jobs Market News

North Korean hackers target Brazilian fintech with sophisticated phishing tactics

4 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
North Korea.png
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link
Phishing Tactics

North Korea-linked malicious actors have been responsible for a third of all phishing activity targeting Brazil since 2020, as the country’s emergence as an influential power has attracted the attention of cyber espionage groups.

“Actors backed by the North Korean government have targeted the Brazilian government and the Brazilian aerospace, technology, and financial services sectors,” Google’s Mandiant and Threat Analysis Group (TAG) divisions said. said in a joint report released this week.

“Similar to targeting interests in other regions, cryptocurrency and fintech companies have come under particular scrutiny, and at least three North Korean groups have targeted Brazilian cryptocurrency and fintech companies.”

Among these groups is a threat actor tracked as UNC4899 (aka Jade Sleet, PUKCHONG, and TraderTraitor), which targeted cryptocurrency professionals with a trojanized Python application containing malware.

The attack chains involve contacting potential targets via social media and sending a harmless PDF document containing a job description for a supposed job opportunity at a well-known cryptocurrency company.

If the target expresses interest in the job posting, the malicious actor sends them a second, harmless PDF document containing a skills questionnaire and instructions to complete a coding task by downloading a project from GitHub.

Cybersecurity

“The project was a trojanized Python application to retrieve cryptocurrency prices that was modified to reach an attacker-controlled domain to retrieve a second-stage payload if specific conditions were met,” Mandiant and TAG researchers said.

This isn’t the first time UNC4899, which was attributed to the 2023 JumpCloud hack, has used this approach. In July 2023, GitHub warned of a social engineering attack that sought to trick employees working at blockchain, cryptocurrency, online gambling and cybersecurity companies into running code hosted in a GitHub repository using fake npm packages.

Job-targeted social engineering campaigns are a recurring theme among North Korean hacking groups, with the tech giant also spotting a campaign orchestrated by a group it tracks under the name PAEKTUSAN to distribute a C++ downloader malware called AGAMEMNON via Microsoft Word attachments embedded in phishing emails.

“In one example, PAEKTUSAN created an account impersonating a human resources manager at a Brazilian aerospace company and used it to send phishing emails to employees at a second Brazilian aerospace company,” the researchers noted, adding that the campaigns are consistent with long-standing activity tracked as Operation Dream Job.

“In a separate campaign, PAEKTUSAN posed as a recruiter for a major U.S. aerospace company and contacted professionals in Brazil and other regions via email and social media about potential job opportunities.”

Google also said it had blocked attempts by another North Korean group dubbed PRONTO to target diplomats with denuclearization- and news-related email lures to trick them into visiting credential-collection pages or providing their login information to view a purported PDF document.

The development comes weeks after Microsoft shed light on a previously undocumented North Korean threat actor named Moonstone Melted Snowwhich targeted individuals and organizations in the software and information technology, education, and defense industrial base sectors with ransomware and espionage attacks.

Notable tactics of Moonstone Sleet include distributing malware via counterfeit npm packages. published on the npm registrymirroring that of UNC4899. That said, the packages associated with the two clusters have distinct code styles and structures.

“The Jade Sleet packages, discovered throughout the summer of 2023, have been designed to work in pairs“each pair being published by a separate npm user account to distribute their malicious functionality,” Checkmarx researchers Tzachi Zornstein and Yehuda Gelb said. said.

Cybersecurity

“In contrast, packages released in late 2023 and early 2024 took a more streamlined, single-package approach that would execute its payload immediately after installation. During Q2 2024, the packages became more complex, with attackers adding obfuscation and also targeting Linux systems.”

Despite the differences, this tactic abuses the trust that users place in open source repositories, allowing threat actors to reach a wider audience and increasing the likelihood that one of their malicious packages could be inadvertently installed by unwitting developers.

This revelation is significant, particularly because it marks an expansion of Moonstone Sleet’s malware distribution mechanism, which previously relied on distributing fake npm packages via LinkedIn and independent websites.

The results also follow the discovery of a new social engineering campaign undertaken by groups linked to North Korea Kimsuky Group in which he impersonated the Reuters news agency to target North Korean human rights activists in order to distribute information-stealing malware under the guise of an interview request, according to Genians.

Did you find this article interesting? Follow us on Twitter  And LinkedIn to read more of the exclusive content we publish.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Projected 37% Rise in Employment by 2026 Despite Economic Challenges

December 19, 2025

Understanding Fintech: Its Importance and Career Prospects

December 10, 2025

Marquette athletes excel in fintech internships

December 3, 2025
Leave A Reply Cancel Reply

Latest news

Basware Acquires Redmap to Enhance AI-Powered Accounts Payable in Australia

December 21, 2025

Is an AI Advisor a Companion or a Financial Hazard?

December 21, 2025

How data, artificial intelligence, and regulations are transforming the future of global fintech

December 21, 2025
News
  • AI in Finance (1,933)
  • Breaking News (184)
  • Corporate Acquisitions (74)
  • Industry Trends (225)
  • Jobs Market News (323)
  • Market Insights (225)
  • Market Rumors (292)
  • Regulatory Updates (186)
  • Startup News (1,251)
  • Technology Innovations (200)
  • X Feed (1)
About US
About US

FintechBits is a blog delivering the latest news and insights in fintech, finance, and technology. We cover breaking news, market trends, innovations, and expert opinions to keep you informed about the future of finance

Facebook X (Twitter) Instagram Pinterest Reddit TikTok
News
  • AI in Finance (1,933)
  • Breaking News (184)
  • Corporate Acquisitions (74)
  • Industry Trends (225)
  • Jobs Market News (323)
  • Market Insights (225)
  • Market Rumors (292)
  • Regulatory Updates (186)
  • Startup News (1,251)
  • Technology Innovations (200)
  • X Feed (1)
Happening Now

November 28, 2024

“ Intentionally collaborative ”: how the Rotman school of U of T leads Innovation Fintech

February 6, 2025

‘1957 Ventures’ to Drive FinTech Innovation in Saudi Arabia

September 10, 2024
  • About FintechBits
  • Advertise With us
  • Contact us
  • Disclaimer
  • Privacy Policy
  • Terms and services
  • BUY OUR EBOOK GUIDE
© 2025 Designed by Fintechbits

Type above and press Enter to search. Press Esc to cancel.