Close Menu
fintechbits
  • News
  • AI
  • Acquisitions
  • Trends
  • Insights
  • Rumors
  • Startups
  • finjobsly

Subscribe to Updates

Get the latest news from Fintechbits.

Trending Now

Strategic Consequences of Concentrated Efforts and the Bella Market Amid Partnership Rumors

September 5, 2025

Weak guidance reveals a setback in AI adoption within Salesforce, leading to a decline in stock after hours, as monetization of AI is progressing slower than anticipated. Here’s the latest update from 24 hours ago.

September 5, 2025

Overview of the Size, Trends, Growth Drivers, and Key Players in India’s Fintech Sector

September 5, 2025

Biden 2.0 Rising? Trump’s brief attack seeks to dispel health rumors, while the far right suggests that issues are evident.

September 5, 2025
Facebook X (Twitter) Instagram
Trending
  • Strategic Consequences of Concentrated Efforts and the Bella Market Amid Partnership Rumors
  • Weak guidance reveals a setback in AI adoption within Salesforce, leading to a decline in stock after hours, as monetization of AI is progressing slower than anticipated. Here’s the latest update from 24 hours ago.
  • Overview of the Size, Trends, Growth Drivers, and Key Players in India’s Fintech Sector
  • Biden 2.0 Rising? Trump’s brief attack seeks to dispel health rumors, while the far right suggests that issues are evident.
  • The pros and cons of utilizing AI for financial management – Newspressnow.com
  • Kapital is the final unicorn in Mexico valued at over $1 billion.
  • Reasons financial institutions emphasize responsibility in the development of GenAI
  • IRDAI reinforces stance: fintechs backed by venture capital are ineligible for insurance licenses.
Facebook X (Twitter) Instagram Pinterest Vimeo
fintechbits
  • News

    Klarna IPO Valuation Analysis in the US Banking Sector

    September 2, 2025

    Robinhood’s IA Investing Tool Digests Launches in the UK

    August 27, 2025

    JMJ Fintech experiences fluctuations despite robust recent financial results and growth strategies

    August 16, 2025

    Revolutionizing Financial Independence through Cryptocurrency Adoption

    August 16, 2025

    Reasons Robinhood is poised for long-term growth in the evolving FinTech and cryptocurrency sectors.

    August 16, 2025
  • AI

    Weak guidance reveals a setback in AI adoption within Salesforce, leading to a decline in stock after hours, as monetization of AI is progressing slower than anticipated. Here’s the latest update from 24 hours ago.

    September 5, 2025

    The pros and cons of utilizing AI for financial management – Newspressnow.com

    September 5, 2025

    Reasons financial institutions emphasize responsibility in the development of GenAI

    September 4, 2025

    Pros and cons of utilizing AI for financial management: Automation streamlines tasks and offers tailored insights, yet raises security concerns.

    September 4, 2025

    The growing emphasis on AI-driven content within financial markets

    September 4, 2025
  • Acquisitions

    The incident involving the Kaustubh Kulkarni movement in Moomoo

    September 3, 2025

    Overview of Acquisitions for US Fintech Companies from the Clifford Chance Guide

    September 2, 2025

    Dentons guides PEAC Solutions in acquiring Fintech Topi

    August 29, 2025

    Truckstop.com purchases the denim division of the transport finish company

    August 24, 2025

    The funding strategy for the Fintech company is secured.

    July 31, 2025
  • Trends

    Overview of the Size, Trends, Growth Drivers, and Key Players in India’s Fintech Sector

    September 5, 2025

    SEF – Wits Global Fintech Conference 2025 Investigates Worldwide Fintech Trends

    September 4, 2025

    The impressive results of PB Fintech underscore the contrast with overall market trends.

    September 4, 2025

    South Korea’s Fintech Market Overview, Trends, and Growth Predictions

    August 30, 2025

    Vietnam’s fintech market projected to exceed 50 billion USD by 2030.

    August 21, 2025
  • Insights

    Kapital is the final unicorn in Mexico valued at over $1 billion.

    September 5, 2025

    Canton RestitySteve Forbes and Peter Schiff Headline New Fintech.tv Series Riding Bulls and Taming Bears Led by David Stryzewski New York, NY / Access Newswire / August 25, 2025 / Fintech.tv has unveiled the debut of Bulls and Taming Bears, a series focused on market analysis and…

    August 28, 2025

    Steve Forbes and Peter Schiff Launch New Fintech.tv Series “Conquering Market Fluctuations” by David Stryzewski – Azentral | The Republic of Arizona

    August 28, 2025

    Updates on Blockchain, Fintech, and Finance from Coinlaw

    August 26, 2025

    The German Finch grape addresses LMA issues following the bafin correction order.

    August 26, 2025
  • Rumors

    Strategic Consequences of Concentrated Efforts and the Bella Market Amid Partnership Rumors

    September 5, 2025

    Biden 2.0 Rising? Trump’s brief attack seeks to dispel health rumors, while the far right suggests that issues are evident.

    September 5, 2025

    Golden State Warriors aim to gain $40 million from Chicago Bulls star in Jonathan Kuminga sign-and-trade deal

    September 2, 2025

    Exclusive: IQSTEL Télécom -Fininch secures $35 million in July – IQSTEL (NASDAQ: IQST)

    August 28, 2025

    Zim discusses market speculation about a possible acquisition.

    August 27, 2025
  • Startups

    IRDAI reinforces stance: fintechs backed by venture capital are ineligible for insurance licenses.

    September 4, 2025

    Amazon finalizes the purchase of the fintech company Axio.

    September 4, 2025

    Fintech Venture Builder OT09 Revealed After Stealth Mode

    September 3, 2025

    Startup Fintech Wych secures $1.5 million to pursue its open banking initiative.

    September 3, 2025

    German fintech Tangany secures 10 million euros for blockchain digital asset custody

    September 2, 2025
  • finjobsly
fintechbits
Home » North Korean hackers target Brazilian fintech with sophisticated phishing tactics
Jobs Market News

North Korean hackers target Brazilian fintech with sophisticated phishing tactics

4 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
North Korea.png
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link
Phishing Tactics

North Korea-linked malicious actors have been responsible for a third of all phishing activity targeting Brazil since 2020, as the country’s emergence as an influential power has attracted the attention of cyber espionage groups.

“Actors backed by the North Korean government have targeted the Brazilian government and the Brazilian aerospace, technology, and financial services sectors,” Google’s Mandiant and Threat Analysis Group (TAG) divisions said. said in a joint report released this week.

“Similar to targeting interests in other regions, cryptocurrency and fintech companies have come under particular scrutiny, and at least three North Korean groups have targeted Brazilian cryptocurrency and fintech companies.”

Among these groups is a threat actor tracked as UNC4899 (aka Jade Sleet, PUKCHONG, and TraderTraitor), which targeted cryptocurrency professionals with a trojanized Python application containing malware.

The attack chains involve contacting potential targets via social media and sending a harmless PDF document containing a job description for a supposed job opportunity at a well-known cryptocurrency company.

If the target expresses interest in the job posting, the malicious actor sends them a second, harmless PDF document containing a skills questionnaire and instructions to complete a coding task by downloading a project from GitHub.

Cybersecurity

“The project was a trojanized Python application to retrieve cryptocurrency prices that was modified to reach an attacker-controlled domain to retrieve a second-stage payload if specific conditions were met,” Mandiant and TAG researchers said.

This isn’t the first time UNC4899, which was attributed to the 2023 JumpCloud hack, has used this approach. In July 2023, GitHub warned of a social engineering attack that sought to trick employees working at blockchain, cryptocurrency, online gambling and cybersecurity companies into running code hosted in a GitHub repository using fake npm packages.

Job-targeted social engineering campaigns are a recurring theme among North Korean hacking groups, with the tech giant also spotting a campaign orchestrated by a group it tracks under the name PAEKTUSAN to distribute a C++ downloader malware called AGAMEMNON via Microsoft Word attachments embedded in phishing emails.

“In one example, PAEKTUSAN created an account impersonating a human resources manager at a Brazilian aerospace company and used it to send phishing emails to employees at a second Brazilian aerospace company,” the researchers noted, adding that the campaigns are consistent with long-standing activity tracked as Operation Dream Job.

“In a separate campaign, PAEKTUSAN posed as a recruiter for a major U.S. aerospace company and contacted professionals in Brazil and other regions via email and social media about potential job opportunities.”

Google also said it had blocked attempts by another North Korean group dubbed PRONTO to target diplomats with denuclearization- and news-related email lures to trick them into visiting credential-collection pages or providing their login information to view a purported PDF document.

The development comes weeks after Microsoft shed light on a previously undocumented North Korean threat actor named Moonstone Melted Snowwhich targeted individuals and organizations in the software and information technology, education, and defense industrial base sectors with ransomware and espionage attacks.

Notable tactics of Moonstone Sleet include distributing malware via counterfeit npm packages. published on the npm registrymirroring that of UNC4899. That said, the packages associated with the two clusters have distinct code styles and structures.

“The Jade Sleet packages, discovered throughout the summer of 2023, have been designed to work in pairs“each pair being published by a separate npm user account to distribute their malicious functionality,” Checkmarx researchers Tzachi Zornstein and Yehuda Gelb said. said.

Cybersecurity

“In contrast, packages released in late 2023 and early 2024 took a more streamlined, single-package approach that would execute its payload immediately after installation. During Q2 2024, the packages became more complex, with attackers adding obfuscation and also targeting Linux systems.”

Despite the differences, this tactic abuses the trust that users place in open source repositories, allowing threat actors to reach a wider audience and increasing the likelihood that one of their malicious packages could be inadvertently installed by unwitting developers.

This revelation is significant, particularly because it marks an expansion of Moonstone Sleet’s malware distribution mechanism, which previously relied on distributing fake npm packages via LinkedIn and independent websites.

The results also follow the discovery of a new social engineering campaign undertaken by groups linked to North Korea Kimsuky Group in which he impersonated the Reuters news agency to target North Korean human rights activists in order to distribute information-stealing malware under the guise of an interview request, according to Genians.

Did you find this article interesting? Follow us on Twitter  And LinkedIn to read more of the exclusive content we publish.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Transforming curiosity into capability – TradingView News

August 27, 2025

Berkeley Students Gain Experience in Fintech through La Royal Gazette

August 21, 2025

Collaboration between Work in Fintech and Payabl to Showcase AI at the Third Fintech Summit

August 21, 2025
Leave A Reply Cancel Reply

Latest news

Strategic Consequences of Concentrated Efforts and the Bella Market Amid Partnership Rumors

September 5, 2025

Weak guidance reveals a setback in AI adoption within Salesforce, leading to a decline in stock after hours, as monetization of AI is progressing slower than anticipated. Here’s the latest update from 24 hours ago.

September 5, 2025

Overview of the Size, Trends, Growth Drivers, and Key Players in India’s Fintech Sector

September 5, 2025
News
  • AI in Finance (1,579)
  • Breaking News (166)
  • Corporate Acquisitions (70)
  • Industry Trends (200)
  • Jobs Market News (305)
  • Market Insights (208)
  • Market Rumors (269)
  • Regulatory Updates (164)
  • Startup News (1,033)
  • Technology Innovations (170)
  • X Feed (1)
About US
About US

FintechBits is a blog delivering the latest news and insights in fintech, finance, and technology. We cover breaking news, market trends, innovations, and expert opinions to keep you informed about the future of finance

Facebook X (Twitter) Instagram Pinterest Reddit TikTok
News
  • AI in Finance (1,579)
  • Breaking News (166)
  • Corporate Acquisitions (70)
  • Industry Trends (200)
  • Jobs Market News (305)
  • Market Insights (208)
  • Market Rumors (269)
  • Regulatory Updates (164)
  • Startup News (1,033)
  • Technology Innovations (170)
  • X Feed (1)
Happening Now

November 28, 2024

“ Intentionally collaborative ”: how the Rotman school of U of T leads Innovation Fintech

February 6, 2025

‘1957 Ventures’ to Drive FinTech Innovation in Saudi Arabia

September 10, 2024
  • About FintechBits
  • Advertise With us
  • Contact us
  • Disclaimer
  • Privacy Policy
  • Terms and services
  • BUY OUR EBOOK GUIDE
© 2025 Designed by Fintechbits

Type above and press Enter to search. Press Esc to cancel.