Google Cloud: North Korea-Linked Crypto Malware Scales Up with AI
Google Cloud’s security arm Mandiant reports that a North Korea-linked group it has tracked since 2018 has been using AI to dramatically expand a crypto-focused malware campaign starting in November 2025. The abuses include automated phishing, social engineering and malware deployment designed to steal wallet credentials and seed phrases, allowing attackers to operate at higher volume with less human effort.
The development matters because AI-driven scaling increases the speed and reach of crypto fraud, putting individual users and smaller exchanges at elevated risk. Mandiant’s findings suggest defenders should expect more sophisticated, personalized lures and rapid campaign iteration. Users are advised to tighten account protections, enable hardware wallets and multi-factor authentication, and rely on official app/store sources while platforms and regulators reassess threat detection and response strategies.