# Jade Sleet

> As of 2026-09-28, Jade Sleet is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning supply chain, apt, malware. ATT&CK coverage spans 77 techniques across 15 tactics in 6 of 6 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1071.001 (Web Protocols), T1195.002 (Compromise Software Supply Chain).

- **Nation:** North Korea (DPRK)
- **Tracked threats:** 6
- **Categories:** SUPPLY_CHAIN, APT, MALWARE, VULNERABILITY
- **As of:** 2026-09-28

## ATT&CK techniques observed

77 techniques observed across 6 of 6 tracked threats. Tactics: Stealth (formerly Defense Evasion) (11), Execution (9), Command and Control (8), Initial Access (7), Resource Development (7), Discovery (6).

- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 4 of 6 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 3 of 6 tracked threats
- [T1195.002](https://intel.threadlinqs.com/technique/T1195.002) Compromise Software Supply Chain — Initial Access — observed in 3 of 6 tracked threats
- [T1204.002](https://intel.threadlinqs.com/technique/T1204.002) User Execution: Malicious File — Execution — observed in 3 of 6 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 6 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 6 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 6 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 6 tracked threats
- [T1059.007](https://intel.threadlinqs.com/technique/T1059.007) JavaScript — Execution — observed in 2 of 6 tracked threats
- [T1070.004](https://intel.threadlinqs.com/technique/T1070.004) File Deletion — Stealth (formerly Defense Evasion) — observed in 2 of 6 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 6 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 6 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 2 of 6 tracked threats
- [T1195.001](https://intel.threadlinqs.com/technique/T1195.001) Compromise Software Dependencies and Development Tools — Initial Access — observed in 2 of 6 tracked threats
- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 2 of 6 tracked threats

## Tracked threats

- [Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)](https://intel.threadlinqs.com/threat/TL-2026-2657) — HIGH
- [Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse](https://intel.threadlinqs.com/threat/TL-2026-2650) — CRITICAL
- [Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors](https://intel.threadlinqs.com/threat/TL-2026-2599) — HIGH
- [Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat Actors](https://intel.threadlinqs.com/threat/TL-2026-0327) — CRITICAL
- [UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure Compromise](https://intel.threadlinqs.com/threat/TL-2026-0202) — CRITICAL
- [Famous Chollima (DPRK) npm Supply Chain — Pastebin Text Steganography Dead-Drop Resolver, 17 Malicious Packages, Vercel C2 Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-0152) — HIGH

## Related CVEs

1 CVE referenced by tracked Jade Sleet activity.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Jade%20Sleet
