UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure Compromise — Threadlinqs Intelligence
As of 2026-05-30, UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure Compromise is a critical-severity apt threat attributed to TraderTraitor (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 37 indicators of compromise.
Threat ID: TL-2026-0202 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: TraderTraitor · North Korea · FINANCIAL
North Korean state-sponsored threat actor UNC4899 (Jade Sleet/TraderTraitor) compromised a major cryptocurrency exchange by socially engineering a developer into downloading a trojanized archive,
UNC4899, a North Korean state-sponsored threat actor also tracked as Jade Sleet, PUKCHONG, Slow Pisces, and TraderTraitor, executed a sophisticated multi-phase attack against a cryptocurrency exchange in 2025, resulting in the theft of several million dollars in digital assets. The attack represents a significant evolution in DPRK cyber operations, introducing novel living-off-the-cloud (LotC) techniques not previously documented.
The assault progressed through seven distinct phases. In Phase 1, the attackers deceived a cryptocurrency firm developer into downloading an archive file under the guise of open-source project collaboration via social engineering on communication platforms. In Phase 2, the developer unknowingly transferred the compromised archive to their corporate workstation using Apple AirDrop, exploiting the seamless peer-to-peer data bridge between personal and work devices — a novel initial access vector not commonly observed in APT campaigns.
Phase 3 involved the victim interacting with the archive contents through an AI-assisted Integrated Development Environment (IDE), which led to execution of embedded malicious Python code. In Phase 4, a binary masquerading as the Kubernetes command-line tool (kubectl) was deployed, establishing contact with attacker-controlled infrastructure and installing a persistent backdoor.
Phase 5 saw the attackers leveraging authenticated sessions and available credentials to penetrate the victim's Google Cloud environments. During Phase 6, extensive lateral movement and privilege escalation occurred. The attackers modified Kubernetes resources tied to the CI/CD platform to inject commands that displayed service account tokens in logs, then obtained a high-privileged CI/CD service account token. They modified MFA policies on bastion hosts, escaped from a privileged pod container to the underlying host, and deployed additional backdoors.
UNC4899 adopted a living-off-the-cloud approach to configure persistence by altering Kubernetes deployment configurations to automatically execute bash commands when new pods were created, downloading backdoors for sustained access. The attackers extracted static database credentials stored insecurely in pod environment variables and used them to access the production database via Cloud SQL Auth Proxy. They executed SQL commands to perform password resets and MFA seed updates for high-value accounts.
In the final phase, the compromised accounts were used to withdraw several million dollars in digital assets. This campaign demonstrates the continued evolution of DPRK crypto-targeting operations, following the JumpCloud supply chain compromise (2023) and the ByBit/Safe{Wallet} heist ($1.5 billion, 2025). The TraderTraitor cluster has stolen over $6.75 billion in cryptocurrency cumulatively, making it one of the most financially impactful APT operations in history.
---
**Revalidated on 2026-03-12**
Post-revalidation note (2026-03-12): All seven attack phases have been independently corroborated by multiple sources following the March 9, 2026 public disclosure. The Google Cloud Threat Horizons Report H1 2026 serves as the authoritative primary source. Additional context from Unit 42's Slow Pisces research (April 2025) confirms the upstream tradecraft — fake coding challenges via LinkedIn deploying RN Loader/RN Stealer on macOS — used to initially compromise the developer. The $2.02B total DPRK crypto theft figure for 2025 (Chainalysis) and the FBI-attributed $1.5B ByBit heist (IC3 PSA, February 2025) place this breach within the context of an industrial-scale state-sponsored cryptocurrency theft campaign. OFAC and DOJ enforcement actions in late 2025 and early 2026 further confirm the TraderTraitor cluster as an active, high-priority threat to the cryptocurrency sector. No factual corrections to the original description are warranted.
Weaknesses (CWE)
CWE-502, CWE-256, CWE-269, CWE-284, CWE-522
Target sectors: cryptocurrency, financial, technology, blockchain, defi
Target regions: Global, North America, East Asia, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 37 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1589, T1593, T1587, T1583, T1566, T1566, T1204, T1059, T1059, T1053