Threat reportAPTTL-2026-0202
UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure Compromise
UNC4899/Jade Sleet Cryptocurrency Exchange Breach via (TL-2026-0202), also tracked as TraderTraitor Campaign 2025, is a critical-severity advanced persistent threat campaign, first published 2026-03-09. It is attributed to TraderTraitor (North Korea) with medium confidence, affects Unnamed Cryptocurrency Exchange Exchange Platform, maps to 24 MITRE ATT&CK techniques (T1021, T1036, T1041), and is covered by 9 detection rules and 37 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 24MITRE ATT&CK
- Actors
- 1TraderTraitor
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 37Indicators of compromise
Key facts for TL-2026-0202
- Threat ID
- TL-2026-0202
- Also known as
- TraderTraitor Campaign 2025, Operation AirDrop Heist
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- TraderTraitor
- Attribution confidence
- MEDIUM
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, financial, technology, blockchain, defi
- Target regions
- Global, North America, East Asia, Europe
- Detection rules
- 9
- Indicators of compromise
- 37
Malware and tooling in UNC4899/Jade Sleet Cryptocurrency Exchange Breach via
Malware and tooling: AppleJeus, RN Loader, RN Stealer, TraderTraitor, Volgmer, Cloud SQL Auth Proxy, FlyVPN
How UNC4899/Jade Sleet Cryptocurrency Exchange Breach via works
North Korean state-sponsored threat actor UNC4899 (Jade Sleet/TraderTraitor) compromised a major cryptocurrency exchange by socially engineering a developer into downloading a trojanized archive, which was then transferred to a corporate workstation via Apple AirDrop. The attack chain progressed through malicious Python execution, Kubernetes container breakout, CI/CD pipeline manipulation, and Cloud SQL database tampering to steal several million dollars in cryptocurrency using novel living-off-the-cloud (LotC) techniques.
UNC4899, a North Korean state-sponsored threat actor also tracked as Jade Sleet, PUKCHONG, Slow Pisces, and TraderTraitor, executed a sophisticated multi-phase attack against a cryptocurrency exchange in 2025, resulting in the theft of several million dollars in digital assets. The attack represents a significant evolution in DPRK cyber operations, introducing novel living-off-the-cloud (LotC) techniques not previously documented.
The assault progressed through seven distinct phases. In Phase 1, the attackers deceived a cryptocurrency firm developer into downloading an archive file under the guise of open-source project collaboration via social engineering on communication platforms. In Phase 2, the developer unknowingly transferred the compromised archive to their corporate workstation using Apple AirDrop, exploiting the seamless peer-to-peer data bridge between personal and work devices — a novel initial access vector not commonly observed in APT campaigns.
Phase 3 involved the victim interacting with the archive contents through an AI-assisted Integrated Development Environment (IDE), which led to execution of embedded malicious Python code. In Phase 4, a binary masquerading as the Kubernetes command-line tool (kubectl) was deployed, establishing contact with attacker-controlled infrastructure and installing a persistent backdoor.
Phase 5 saw the attackers leveraging authenticated sessions and available credentials to penetrate the victim's Google Cloud environments. During Phase 6, extensive lateral movement and privilege escalation occurred. The attackers modified Kubernetes resources tied to the CI/CD platform to inject commands that displayed service account tokens in logs, then obtained a high-privileged CI/CD service account token. They modified MFA policies on bastion hosts, escaped from a privileged pod container to the underlying host, and deployed additional backdoors.
UNC4899 adopted a living-off-the-cloud approach to configure persistence by altering Kubernetes deployment configurations to automatically execute bash commands when new pods were created, downloading backdoors for sustained access. The attackers extracted static database credentials stored insecurely in pod environment variables and used them to access the production database via Cloud SQL Auth Proxy. They executed SQL commands to perform password resets and MFA seed updates for high-value accounts.
In the final phase, the compromised accounts were used to withdraw several million dollars in digital assets. This campaign demonstrates the continued evolution of DPRK crypto-targeting operations, following the JumpCloud supply chain compromise (2023) and the ByBit/Safe{Wallet} heist ($1.5 billion, 2025). The TraderTraitor cluster has stolen over $6.75 billion in cryptocurrency cumulatively, making it one of the most financially impactful APT operations in history.
---
**Revalidated on 2026-03-12**
Post-revalidation note (2026-03-12): All seven attack phases have been independently corroborated by multiple sources following the March 9, 2026 public disclosure. The Google Cloud Threat Horizons Report H1 2026 serves as the authoritative primary source. Additional context from Unit 42's Slow Pisces research (April 2025) confirms the upstream tradecraft — fake coding challenges via LinkedIn deploying RN Loader/RN Stealer on macOS — used to initially compromise the developer. The $2.02B total DPRK crypto theft figure for 2025 (Chainalysis) and the FBI-attributed $1.5B ByBit heist (IC3 PSA, February 2025) place this breach within the context of an industrial-scale state-sponsored cryptocurrency theft campaign. OFAC and DOJ enforcement actions in late 2025 and early 2026 further confirm the TraderTraitor cluster as an active, high-priority threat to the cryptocurrency sector. No factual corrections to the original description are warranted.
MITRE ATT&CK techniques used in TL-2026-0202
lateral-movement
T1021 Remote Services; T1550 Use Alternate Authentication Material
defense-evasion
T1036 Masquerading; T1078 Valid Accounts
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
credential-access
T1528 Steal Application Access Token; T1552 Unsecured Credentials
collection
impact
T1565 Data Manipulation; T1657 Financial Theft
initial-access
discovery
T1580 Cloud Infrastructure Discovery; T1613 Container and Resource Discovery
resource-development
T1583 Acquire Infrastructure; T1587 Develop Capabilities
reconnaissance
T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains
privilege-escalation
Affected products and versions in UNC4899/Jade Sleet Cryptocurrency Exchange Breach via
- Unnamed Cryptocurrency Exchange — Exchange Platform
Vulnerable versions: Cloud-hosted production environment - Google — Google Cloud Platform (GKE, Cloud SQL)
Vulnerable versions: Misconfigured deployments
Fixed in: Properly configured with Workload Identity - Apple — AirDrop
Vulnerable versions: All versions with unrestricted sharing
Fixed in: Contacts Only or Disabled - Kubernetes — Kubernetes
Vulnerable versions: Deployments with overprivileged pods
Fixed in: Hardened with Pod Security Standards
Remediation for UNC4899/Jade Sleet Cryptocurrency Exchange Breach via
Immediate actions
- Block all known TraderTraitor C2 domains and IPs at perimeter firewalls
- Disable Apple AirDrop on corporate macOS devices via MDM policy
- Audit Kubernetes deployment configurations for unauthorized command injection
- Rotate all CI/CD service account tokens and cloud credentials immediately
- Review Cloud SQL Auth Proxy access logs for unauthorized connections
- Scan for kubectl-masquerading binaries on developer workstations
Workarounds
- Restrict AirDrop to contacts-only or disable entirely on work devices
- Enable Kubernetes audit logging for all API server operations
- Implement Cloud SQL IAM database authentication instead of static credentials
- Use GKE Workload Identity to eliminate service account key distribution
Longer-term hardening
- Implement strict BYOD policies prohibiting P2P file transfers to corporate devices
- Deploy container runtime security with escape detection (Falco, Sysdig)
- Enforce least-privilege IAM for Kubernetes service accounts
- Store database credentials in secrets managers, not environment variables
- Implement network segmentation between CI/CD, Kubernetes, and production databases
- Deploy behavioral EDR on all developer workstations with AI-IDE monitoring
- Implement MFA hardware tokens resistant to seed extraction
Weaknesses (CWE) in UNC4899/Jade Sleet Cryptocurrency Exchange Breach via
Timeline of UNC4899/Jade Sleet Cryptocurrency Exchange Breach via
- CISA, FBI, and US Treasury publish joint advisory AA22-108A on TraderTraitor, warning of DPRK state-sponsored APT targeting blockchain companies
- UNC4899/TraderTraitor compromises JumpCloud via spear-phishing, using it as supply chain pivot to target cryptocurrency customers
- TraderTraitor cluster executes ByBit/Safe{Wallet} heist, stealing approximately $1.5 billion in Ethereum — largest single crypto theft in history
- Palo Alto Unit 42 publishes ''Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware,'' documenting RN Loader and RN Stealer deployment against crypto developers via LinkedIn-based fake recruitment — directly relevant tradecraft to the TL-2026-0202 social engineering phase. [Source: https://unit42.paloaltonetworks.com/slow-pisces-new-custom-malware/]
- Developer transfers compromised archive from personal device to corporate workstation via Apple AirDrop P2P file transfer
- UNC4899 operators socially engineer cryptocurrency exchange developer, deceiving them into downloading trojanized archive disguised as open-source project collaboration
- Victim interacts with archive contents in AI-assisted IDE, executing embedded malicious Python code; kubectl-masquerading binary establishes C2 communication
- Attackers leverage authenticated sessions and stolen credentials to penetrate victim Google Cloud environments, begin reconnaissance of services, projects, and bastion hosts
- Kubernetes CI/CD resources modified to inject commands displaying service account tokens in logs; high-privileged CI/CD service account token obtained
- Attackers escape from privileged pod container to underlying host, deploy backdoor; modify Kubernetes deployment configs for LotC persistence
- Static database credentials extracted from pod environment variables; production database accessed via Cloud SQL Auth Proxy; SQL commands executed for password resets and MFA seed updates on high-value accounts
- Compromised high-value accounts used to withdraw several million dollars in cryptocurrency from exchange
- Chainalysis and The Hacker News report DPRK-linked groups stole $2.02 billion in cryptocurrency during 2025, establishing the scale of state-sponsored crypto theft operations in which this breach was one component. [Source: https://thehackernews.com/2025/12/north-korea-linked-hackers-steal-202.html]
- 38 North publishes ''From Digital Kleptocracy to Rogue Crypto-Superpower,'' a strategic analysis of DPRK''s evolution into a state-level cryptocurrency theft apparatus, providing geopolitical context for UNC4899 operations. [Source: https://www.38north.org/2026/01/from-digital-kleptocracy-to-rogue-crypto-superpower/]
- Ctrl-Alt-Intel researchers identify DPRK intrusion chains through exposed open-directories, linking campaign to TraderTraitor cluster
- Google Cloud publishes Cloud Threat Horizons Report H1 2026, which includes the full Mandiant technical analysis of the UNC4899 AirDrop attack chain and living-off-the-cloud techniques, confirming all phases described in TL-2026-0202. [Source: https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026]
- Mandiant/Google publishes detailed technical analysis of UNC4899 AirDrop attack chain, documenting novel living-off-the-cloud techniques
- As of 2026-05-29, TL-2026-0202 remains ACTIVE: the UNC4899/TraderTraitor (Lazarus, DPRK) actor is still operating, attributed to the ~$292M April 18, 2026 KelpDAO/LayerZero exploit and ~76% of 2026 crypto-hack losses (TRM Labs). No CVE/patch applies; the AirDrop + living-off-the-cloud TTPs are unmitigated and the actor remains undisrupted despite OFAC sanctions.
Sources cited for UNC4899/Jade Sleet Cryptocurrency Exchange Breach via
- UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device
- CISA Advisory AA22-108A: TraderTraitor — North Korean State-Sponsored APT Targets Blockchain Companies
- TraderTraitor Deep Dive — Wiz Threat Research
- North Korea-Linked Hackers Target Crypto Supply Chain in Cloud Breach
- CISA AppleJeus Advisory AA21-048A
- Suspected DPRK Threat Actors Compromise Crypto Firms, Steal Keys and Cloud Assets
- North Korean Hackers Using Fake Job Offers to Breach Cloud Systems
- Google Cloud, AWS Targeted by North Korean Hacking Group
- From Digital Kleptocracy to Rogue Crypto-Superpower — 38 North Analysis
- 2025 Crypto Theft Reaches $3.4 Billion — Chainalysis
Detection coverage for TL-2026-0202
As of 2026-03-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0202 across Splunk SPL, Microsoft KQL and Sigma, covering 37 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.