Close Menu
fintechbits
  • News
  • AI
  • Acquisitions
  • Trends
  • Insights
  • Rumors
  • Startups
  • finjobsly

Subscribe to Updates

Get the latest news from Fintechbits.

Trending Now

Blume Ventures and Piper Serica Lead $3.4 Million Investment Round for Fintech Startup Mysa

January 27, 2026

Zocks secures $45 million to grow AI offerings for financial advisors

January 27, 2026

The use of Shadow AI tools and chatbots is prevalent in healthcare facilities.

January 27, 2026

The integration of AI into finance is reshaping the global landscape.

January 27, 2026
Facebook X (Twitter) Instagram
Trending
  • Blume Ventures and Piper Serica Lead $3.4 Million Investment Round for Fintech Startup Mysa
  • Zocks secures $45 million to grow AI offerings for financial advisors
  • The use of Shadow AI tools and chatbots is prevalent in healthcare facilities.
  • The integration of AI into finance is reshaping the global landscape.
  • Mysa secures $3.4 million funding from Blume Ventures and Piper Serica.
  • Mine secures $14 million in funding to introduce AI-powered personal finance assistant
  • AI’s Impact on Finance: The Transformative Role of Agentic AI in Banking Technology, Alongside Challenges in Comprehending and Implementing These Tools.
  • Michigan Financial Services Regulator Highlights Best Practices for AI Compliance in the Industry
Facebook X (Twitter) Instagram Pinterest Vimeo
fintechbits
  • News

    Headlines from KUTV covering news, weather, sports, and breaking updates in Salt Lake City

    January 19, 2026

    Kuda Reduces Losses to $5.8 Million as Fintech Concentrates on Achieving Profitability

    January 14, 2026

    Fintech Titan or Overhyped Relic?

    January 7, 2026

    PayPal joins other fintech companies benefiting from Trump-era deregulation.

    December 16, 2025

    Zilch, the fintech unicorn, secures payment license from city regulator.

    December 10, 2025
  • AI

    Zocks secures $45 million to grow AI offerings for financial advisors

    January 27, 2026

    The use of Shadow AI tools and chatbots is prevalent in healthcare facilities.

    January 27, 2026

    The integration of AI into finance is reshaping the global landscape.

    January 27, 2026

    Mine secures $14 million in funding to introduce AI-powered personal finance assistant

    January 27, 2026

    AI’s Impact on Finance: The Transformative Role of Agentic AI in Banking Technology, Alongside Challenges in Comprehending and Implementing These Tools.

    January 27, 2026
  • Acquisitions

    Capital One’s $5 billion purchase of fintech Brex may prove to be another brilliant move by billionaire Richard Fairbank.

    January 24, 2026

    Fintech Partnership Enhances UST’s Digital Banking Goals

    January 20, 2026

    CoinGecko is reportedly exploring a sale valued at $500 million.

    January 16, 2026

    Flutterwave acquires Nigerian Mono in a unique exit for African fintech.

    January 6, 2026

    MergersandAcquisitions.net publishes a comprehensive report on trends and analyses in financial services and fintech mergers and acquisitions.

    December 23, 2025
  • Trends

    Key Stablecoin Trends to Monitor in 2026 – Fintech Schweiz Digital Finance News

    January 21, 2026

    Trends in Emerging Fintech Technologies Emphasize Wealth Management

    January 8, 2026

    GCC Fintech Landscape: Embracing Open Banking, Nurturing Startups, and Investment Patterns

    January 7, 2026

    eLEND Solutions Introduces Fintech Platform to Simplify Financing and Credit for Dealerships – Pete MacInnis

    January 6, 2026

    Saudi Arabian fintech sector projected to grow to $4.8 billion by 2034

    December 22, 2025
  • Insights

    Climate change overwhelms the insurance industry.

    January 23, 2026

    Capital One to purchase fintech startup Brex for $5.15 billion, as announced in a definitive agreement on Thursday.

    January 23, 2026

    Insights on the Fintech.TV Collaboration with Datavault AI Inc. Stock (DVLT)

    January 17, 2026

    Wealthfront aims for a valuation of as much as $2.05 billion in its U.S. IPO, according to CTV News.

    January 7, 2026

    New UNF collaboration seeks to promote fintech innovation – Action News Jax

    December 27, 2025
  • Rumors

    SpaceX Considers Initial Public Offering, Spirit Airlines Owner Explores Private Equity, and Other Speculations

    January 25, 2026

    Collapse of Livestock Markets Amid Tumultuous Rumors

    January 23, 2026

    Crypto schools draw interest amid speculation regarding UAE initiatives.

    January 23, 2026

    Is Coinbase exploring the acquisition of BVNK to enhance its Stablecoin growth?

    January 20, 2026

    JD-SW refutes speculation about issuing RMB10 billion in Dim Sum bonds, according to Financial News.

    January 15, 2026
  • Startups

    Blume Ventures and Piper Serica Lead $3.4 Million Investment Round for Fintech Startup Mysa

    January 27, 2026

    Mysa secures $3.4 million funding from Blume Ventures and Piper Serica.

    January 27, 2026

    Kollab invests $2 million in the Philippine payments startup PayRex

    January 26, 2026

    St. Gallen introduces online platform for starting a business

    January 26, 2026

    From financial technology to electric vehicles, startup funding gains momentum in January.

    January 24, 2026
  • finjobsly
fintechbits
Home » North Korean hackers target Brazilian fintech with sophisticated phishing tactics
Jobs Market News

North Korean hackers target Brazilian fintech with sophisticated phishing tactics

4 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
North Korea.png
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link
Phishing Tactics

North Korea-linked malicious actors have been responsible for a third of all phishing activity targeting Brazil since 2020, as the country’s emergence as an influential power has attracted the attention of cyber espionage groups.

“Actors backed by the North Korean government have targeted the Brazilian government and the Brazilian aerospace, technology, and financial services sectors,” Google’s Mandiant and Threat Analysis Group (TAG) divisions said. said in a joint report released this week.

“Similar to targeting interests in other regions, cryptocurrency and fintech companies have come under particular scrutiny, and at least three North Korean groups have targeted Brazilian cryptocurrency and fintech companies.”

Among these groups is a threat actor tracked as UNC4899 (aka Jade Sleet, PUKCHONG, and TraderTraitor), which targeted cryptocurrency professionals with a trojanized Python application containing malware.

The attack chains involve contacting potential targets via social media and sending a harmless PDF document containing a job description for a supposed job opportunity at a well-known cryptocurrency company.

If the target expresses interest in the job posting, the malicious actor sends them a second, harmless PDF document containing a skills questionnaire and instructions to complete a coding task by downloading a project from GitHub.

Cybersecurity

“The project was a trojanized Python application to retrieve cryptocurrency prices that was modified to reach an attacker-controlled domain to retrieve a second-stage payload if specific conditions were met,” Mandiant and TAG researchers said.

This isn’t the first time UNC4899, which was attributed to the 2023 JumpCloud hack, has used this approach. In July 2023, GitHub warned of a social engineering attack that sought to trick employees working at blockchain, cryptocurrency, online gambling and cybersecurity companies into running code hosted in a GitHub repository using fake npm packages.

Job-targeted social engineering campaigns are a recurring theme among North Korean hacking groups, with the tech giant also spotting a campaign orchestrated by a group it tracks under the name PAEKTUSAN to distribute a C++ downloader malware called AGAMEMNON via Microsoft Word attachments embedded in phishing emails.

“In one example, PAEKTUSAN created an account impersonating a human resources manager at a Brazilian aerospace company and used it to send phishing emails to employees at a second Brazilian aerospace company,” the researchers noted, adding that the campaigns are consistent with long-standing activity tracked as Operation Dream Job.

“In a separate campaign, PAEKTUSAN posed as a recruiter for a major U.S. aerospace company and contacted professionals in Brazil and other regions via email and social media about potential job opportunities.”

Google also said it had blocked attempts by another North Korean group dubbed PRONTO to target diplomats with denuclearization- and news-related email lures to trick them into visiting credential-collection pages or providing their login information to view a purported PDF document.

The development comes weeks after Microsoft shed light on a previously undocumented North Korean threat actor named Moonstone Melted Snowwhich targeted individuals and organizations in the software and information technology, education, and defense industrial base sectors with ransomware and espionage attacks.

Notable tactics of Moonstone Sleet include distributing malware via counterfeit npm packages. published on the npm registrymirroring that of UNC4899. That said, the packages associated with the two clusters have distinct code styles and structures.

“The Jade Sleet packages, discovered throughout the summer of 2023, have been designed to work in pairs“each pair being published by a separate npm user account to distribute their malicious functionality,” Checkmarx researchers Tzachi Zornstein and Yehuda Gelb said. said.

Cybersecurity

“In contrast, packages released in late 2023 and early 2024 took a more streamlined, single-package approach that would execute its payload immediately after installation. During Q2 2024, the packages became more complex, with attackers adding obfuscation and also targeting Linux systems.”

Despite the differences, this tactic abuses the trust that users place in open source repositories, allowing threat actors to reach a wider audience and increasing the likelihood that one of their malicious packages could be inadvertently installed by unwitting developers.

This revelation is significant, particularly because it marks an expansion of Moonstone Sleet’s malware distribution mechanism, which previously relied on distributing fake npm packages via LinkedIn and independent websites.

The results also follow the discovery of a new social engineering campaign undertaken by groups linked to North Korea Kimsuky Group in which he impersonated the Reuters news agency to target North Korean human rights activists in order to distribute information-stealing malware under the guise of an interview request, according to Genians.

Did you find this article interesting? Follow us on Twitter  And LinkedIn to read more of the exclusive content we publish.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

FinTech Company Provides AI-Resistant Skills and Employment Options

January 22, 2026

Career Opportunities in Blockchain and FinTech by 2026

January 21, 2026

Uttar Pradesh’s Transition to a Digital Economy: The Fintech Transformation

January 20, 2026
Leave A Reply Cancel Reply

Latest news

Blume Ventures and Piper Serica Lead $3.4 Million Investment Round for Fintech Startup Mysa

January 27, 2026

Zocks secures $45 million to grow AI offerings for financial advisors

January 27, 2026

The use of Shadow AI tools and chatbots is prevalent in healthcare facilities.

January 27, 2026
News
  • AI in Finance (2,047)
  • Breaking News (187)
  • Corporate Acquisitions (79)
  • Industry Trends (230)
  • Jobs Market News (332)
  • Market Insights (231)
  • Market Rumors (302)
  • Regulatory Updates (194)
  • Startup News (1,293)
  • Technology Innovations (202)
  • X Feed (1)
About US
About US

FintechBits is a blog delivering the latest news and insights in fintech, finance, and technology. We cover breaking news, market trends, innovations, and expert opinions to keep you informed about the future of finance

Facebook X (Twitter) Instagram Pinterest Reddit TikTok
News
  • AI in Finance (2,047)
  • Breaking News (187)
  • Corporate Acquisitions (79)
  • Industry Trends (230)
  • Jobs Market News (332)
  • Market Insights (231)
  • Market Rumors (302)
  • Regulatory Updates (194)
  • Startup News (1,293)
  • Technology Innovations (202)
  • X Feed (1)
Happening Now

November 28, 2024

“ Intentionally collaborative ”: how the Rotman school of U of T leads Innovation Fintech

February 6, 2025

‘1957 Ventures’ to Drive FinTech Innovation in Saudi Arabia

September 10, 2024
  • About FintechBits
  • Advertise With us
  • Contact us
  • Disclaimer
  • Privacy Policy
  • Terms and services
  • BUY OUR EBOOK GUIDE
© 2026 Designed by Fintechbits

Type above and press Enter to search. Press Esc to cancel.