Threat reportAPTTL-2026-0202

UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure Compromise

criticalACTIVE

UNC4899/Jade Sleet Cryptocurrency Exchange Breach via (TL-2026-0202), also tracked as TraderTraitor Campaign 2025, is a critical-severity advanced persistent threat campaign, first published 2026-03-09. It is attributed to TraderTraitor (North Korea) with medium confidence, affects Unnamed Cryptocurrency Exchange Exchange Platform, maps to 24 MITRE ATT&CK techniques (T1021, T1036, T1041), and is covered by 9 detection rules and 37 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
1TraderTraitor
Detection rules
9SPL · KQL · Sigma
IOCs
37Indicators of compromise

Key facts for TL-2026-0202

Threat ID
TL-2026-0202
Also known as
TraderTraitor Campaign 2025, Operation AirDrop Heist
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
TraderTraitor
Attribution confidence
MEDIUM
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
cryptocurrency, financial, technology, blockchain, defi
Target regions
Global, North America, East Asia, Europe
Detection rules
9
Indicators of compromise
37

Malware and tooling in UNC4899/Jade Sleet Cryptocurrency Exchange Breach via

Malware and tooling: AppleJeus, RN Loader, RN Stealer, TraderTraitor, Volgmer, Cloud SQL Auth Proxy, FlyVPN

How UNC4899/Jade Sleet Cryptocurrency Exchange Breach via works

North Korean state-sponsored threat actor UNC4899 (Jade Sleet/TraderTraitor) compromised a major cryptocurrency exchange by socially engineering a developer into downloading a trojanized archive, which was then transferred to a corporate workstation via Apple AirDrop. The attack chain progressed through malicious Python execution, Kubernetes container breakout, CI/CD pipeline manipulation, and Cloud SQL database tampering to steal several million dollars in cryptocurrency using novel living-off-the-cloud (LotC) techniques.

UNC4899, a North Korean state-sponsored threat actor also tracked as Jade Sleet, PUKCHONG, Slow Pisces, and TraderTraitor, executed a sophisticated multi-phase attack against a cryptocurrency exchange in 2025, resulting in the theft of several million dollars in digital assets. The attack represents a significant evolution in DPRK cyber operations, introducing novel living-off-the-cloud (LotC) techniques not previously documented.

The assault progressed through seven distinct phases. In Phase 1, the attackers deceived a cryptocurrency firm developer into downloading an archive file under the guise of open-source project collaboration via social engineering on communication platforms. In Phase 2, the developer unknowingly transferred the compromised archive to their corporate workstation using Apple AirDrop, exploiting the seamless peer-to-peer data bridge between personal and work devices — a novel initial access vector not commonly observed in APT campaigns.

Phase 3 involved the victim interacting with the archive contents through an AI-assisted Integrated Development Environment (IDE), which led to execution of embedded malicious Python code. In Phase 4, a binary masquerading as the Kubernetes command-line tool (kubectl) was deployed, establishing contact with attacker-controlled infrastructure and installing a persistent backdoor.

Phase 5 saw the attackers leveraging authenticated sessions and available credentials to penetrate the victim's Google Cloud environments. During Phase 6, extensive lateral movement and privilege escalation occurred. The attackers modified Kubernetes resources tied to the CI/CD platform to inject commands that displayed service account tokens in logs, then obtained a high-privileged CI/CD service account token. They modified MFA policies on bastion hosts, escaped from a privileged pod container to the underlying host, and deployed additional backdoors.

UNC4899 adopted a living-off-the-cloud approach to configure persistence by altering Kubernetes deployment configurations to automatically execute bash commands when new pods were created, downloading backdoors for sustained access. The attackers extracted static database credentials stored insecurely in pod environment variables and used them to access the production database via Cloud SQL Auth Proxy. They executed SQL commands to perform password resets and MFA seed updates for high-value accounts.

In the final phase, the compromised accounts were used to withdraw several million dollars in digital assets. This campaign demonstrates the continued evolution of DPRK crypto-targeting operations, following the JumpCloud supply chain compromise (2023) and the ByBit/Safe{Wallet} heist ($1.5 billion, 2025). The TraderTraitor cluster has stolen over $6.75 billion in cryptocurrency cumulatively, making it one of the most financially impactful APT operations in history.

---

**Revalidated on 2026-03-12**

Post-revalidation note (2026-03-12): All seven attack phases have been independently corroborated by multiple sources following the March 9, 2026 public disclosure. The Google Cloud Threat Horizons Report H1 2026 serves as the authoritative primary source. Additional context from Unit 42's Slow Pisces research (April 2025) confirms the upstream tradecraft — fake coding challenges via LinkedIn deploying RN Loader/RN Stealer on macOS — used to initially compromise the developer. The $2.02B total DPRK crypto theft figure for 2025 (Chainalysis) and the FBI-attributed $1.5B ByBit heist (IC3 PSA, February 2025) place this breach within the context of an industrial-scale state-sponsored cryptocurrency theft campaign. OFAC and DOJ enforcement actions in late 2025 and early 2026 further confirm the TraderTraitor cluster as an active, high-priority threat to the cryptocurrency sector. No factual corrections to the original description are warranted.

MITRE ATT&CK techniques used in TL-2026-0202

lateral-movement

T1021 Remote Services; T1550 Use Alternate Authentication Material

defense-evasion

T1036 Masquerading; T1078 Valid Accounts

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

credential-access

T1528 Steal Application Access Token; T1552 Unsecured Credentials

collection

T1530 Data from Cloud Storage

impact

T1565 Data Manipulation; T1657 Financial Theft

initial-access

T1566 Phishing

discovery

T1580 Cloud Infrastructure Discovery; T1613 Container and Resource Discovery

resource-development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

reconnaissance

T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains

privilege-escalation

T1611 Escape to Host

Affected products and versions in UNC4899/Jade Sleet Cryptocurrency Exchange Breach via

  • Unnamed Cryptocurrency Exchange — Exchange Platform
    Vulnerable versions: Cloud-hosted production environment
  • Google — Google Cloud Platform (GKE, Cloud SQL)
    Vulnerable versions: Misconfigured deployments
    Fixed in: Properly configured with Workload Identity
  • Apple — AirDrop
    Vulnerable versions: All versions with unrestricted sharing
    Fixed in: Contacts Only or Disabled
  • Kubernetes — Kubernetes
    Vulnerable versions: Deployments with overprivileged pods
    Fixed in: Hardened with Pod Security Standards

Remediation for UNC4899/Jade Sleet Cryptocurrency Exchange Breach via

Immediate actions

  • Block all known TraderTraitor C2 domains and IPs at perimeter firewalls
  • Disable Apple AirDrop on corporate macOS devices via MDM policy
  • Audit Kubernetes deployment configurations for unauthorized command injection
  • Rotate all CI/CD service account tokens and cloud credentials immediately
  • Review Cloud SQL Auth Proxy access logs for unauthorized connections
  • Scan for kubectl-masquerading binaries on developer workstations

Workarounds

  • Restrict AirDrop to contacts-only or disable entirely on work devices
  • Enable Kubernetes audit logging for all API server operations
  • Implement Cloud SQL IAM database authentication instead of static credentials
  • Use GKE Workload Identity to eliminate service account key distribution

Longer-term hardening

  • Implement strict BYOD policies prohibiting P2P file transfers to corporate devices
  • Deploy container runtime security with escape detection (Falco, Sysdig)
  • Enforce least-privilege IAM for Kubernetes service accounts
  • Store database credentials in secrets managers, not environment variables
  • Implement network segmentation between CI/CD, Kubernetes, and production databases
  • Deploy behavioral EDR on all developer workstations with AI-IDE monitoring
  • Implement MFA hardware tokens resistant to seed extraction

Weaknesses (CWE) in UNC4899/Jade Sleet Cryptocurrency Exchange Breach via

CWE-502, CWE-256, CWE-269, CWE-284, CWE-522

Timeline of UNC4899/Jade Sleet Cryptocurrency Exchange Breach via

  • CISA, FBI, and US Treasury publish joint advisory AA22-108A on TraderTraitor, warning of DPRK state-sponsored APT targeting blockchain companies
  • UNC4899/TraderTraitor compromises JumpCloud via spear-phishing, using it as supply chain pivot to target cryptocurrency customers
  • TraderTraitor cluster executes ByBit/Safe{Wallet} heist, stealing approximately $1.5 billion in Ethereum — largest single crypto theft in history
  • Palo Alto Unit 42 publishes ''Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware,'' documenting RN Loader and RN Stealer deployment against crypto developers via LinkedIn-based fake recruitment — directly relevant tradecraft to the TL-2026-0202 social engineering phase. [Source: https://unit42.paloaltonetworks.com/slow-pisces-new-custom-malware/]
  • Developer transfers compromised archive from personal device to corporate workstation via Apple AirDrop P2P file transfer
  • UNC4899 operators socially engineer cryptocurrency exchange developer, deceiving them into downloading trojanized archive disguised as open-source project collaboration
  • Victim interacts with archive contents in AI-assisted IDE, executing embedded malicious Python code; kubectl-masquerading binary establishes C2 communication
  • Attackers leverage authenticated sessions and stolen credentials to penetrate victim Google Cloud environments, begin reconnaissance of services, projects, and bastion hosts
  • Kubernetes CI/CD resources modified to inject commands displaying service account tokens in logs; high-privileged CI/CD service account token obtained
  • Attackers escape from privileged pod container to underlying host, deploy backdoor; modify Kubernetes deployment configs for LotC persistence
  • Static database credentials extracted from pod environment variables; production database accessed via Cloud SQL Auth Proxy; SQL commands executed for password resets and MFA seed updates on high-value accounts
  • Compromised high-value accounts used to withdraw several million dollars in cryptocurrency from exchange
  • Chainalysis and The Hacker News report DPRK-linked groups stole $2.02 billion in cryptocurrency during 2025, establishing the scale of state-sponsored crypto theft operations in which this breach was one component. [Source: https://thehackernews.com/2025/12/north-korea-linked-hackers-steal-202.html]
  • 38 North publishes ''From Digital Kleptocracy to Rogue Crypto-Superpower,'' a strategic analysis of DPRK''s evolution into a state-level cryptocurrency theft apparatus, providing geopolitical context for UNC4899 operations. [Source: https://www.38north.org/2026/01/from-digital-kleptocracy-to-rogue-crypto-superpower/]
  • Ctrl-Alt-Intel researchers identify DPRK intrusion chains through exposed open-directories, linking campaign to TraderTraitor cluster
  • Google Cloud publishes Cloud Threat Horizons Report H1 2026, which includes the full Mandiant technical analysis of the UNC4899 AirDrop attack chain and living-off-the-cloud techniques, confirming all phases described in TL-2026-0202. [Source: https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026]
  • Mandiant/Google publishes detailed technical analysis of UNC4899 AirDrop attack chain, documenting novel living-off-the-cloud techniques
  • As of 2026-05-29, TL-2026-0202 remains ACTIVE: the UNC4899/TraderTraitor (Lazarus, DPRK) actor is still operating, attributed to the ~$292M April 18, 2026 KelpDAO/LayerZero exploit and ~76% of 2026 crypto-hack losses (TRM Labs). No CVE/patch applies; the AirDrop + living-off-the-cloud TTPs are unmitigated and the actor remains undisrupted despite OFAC sanctions.

Sources cited for UNC4899/Jade Sleet Cryptocurrency Exchange Breach via

Detection coverage for TL-2026-0202

As of 2026-03-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0202 across Splunk SPL, Microsoft KQL and Sigma, covering 37 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
37 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats