# UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure Compromise

> North Korean state-sponsored threat actor UNC4899 (Jade Sleet/TraderTraitor) compromised a major cryptocurrency exchange by socially engineering a developer into downloading a trojanized archive, which was then transferred to a corporate workstation via Apple AirDrop. The attack chain progressed through malicious Python execution, Kubernetes container breakout, CI/CD pipeline manipulation, and Cloud SQL database tampering to steal several million dollars in cryptocurrency using novel living-off-the-cloud (LotC) techniques.

- **Published:** 2026-03-09T12:00:00Z
- **Last reviewed:** 2026-03-09T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0202
- **ID:** TL-2026-0202
- **Severity:** CRITICAL
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** TraderTraitor (North Korea)
- **Detections:** 9 · **IOCs:** 37 (full data via the Threadlinqs MCP server — Purple tier)

## Description

UNC4899, a North Korean state-sponsored threat actor also tracked as Jade Sleet, PUKCHONG, Slow Pisces, and TraderTraitor, executed a sophisticated multi-phase attack against a cryptocurrency exchange in 2025, resulting in the theft of several million dollars in digital assets. The attack represents a significant evolution in DPRK cyber operations, introducing novel living-off-the-cloud (LotC) techniques not previously documented.

The assault progressed through seven distinct phases. In Phase 1, the attackers deceived a cryptocurrency firm developer into downloading an archive file under the guise of open-source project collaboration via social engineering on communication platforms. In Phase 2, the developer unknowingly transferred the compromised archive to their corporate workstation using Apple AirDrop, exploiting the seamless peer-to-peer data bridge between personal and work devices — a novel initial access vector not commonly observed in APT campaigns.

Phase 3 involved the victim interacting with the archive contents through an AI-assisted Integrated Development Environment (IDE), which led to execution of embedded malicious Python code. In Phase 4, a binary masquerading as the Kubernetes command-line tool (kubectl) was deployed, establishing contact with attacker-controlled infrastructure and installing a persistent backdoor.

Phase 5 saw the attackers leveraging authenticated sessions and available credentials to penetrate the victim's Google Cloud environments. During Phase 6, extensive lateral movement and privilege escalation occurred. The attackers modified Kubernetes resources tied to the CI/CD platform to inject commands that displayed service account tokens in logs, then obtained a high-privileged CI/CD service account token. They modified MFA policies on bastion hosts, escaped from a privileged pod container to the underlying host, and deployed additional backdoors.

UNC4899 adopted a living-off-the-cloud approach to configure persistence by altering Kubernetes deployment configurations to automatically execute bash commands when new pods were created, downloading backdoors for sustained access. The attackers extracted static database credentials stored insecurely in pod environment variables and used them to access the production database via Cloud SQL Auth Proxy. They executed SQL commands to perform password resets and MFA seed updates for high-value accounts.

In the final phase, the compromised accounts were used to withdraw several million dollars in digital assets. This campaign demonstrates the continued evolution of DPRK crypto-targeting operations, following the JumpCloud supply chain compromise (2023) and the ByBit/Safe{Wallet} heist ($1.5 billion, 2025). The TraderTraitor cluster has stolen over $6.75 billion in cryptocurrency cumulatively, making it one of the most financially impactful APT operations in history.

---

**Revalidated on 2026-03-12**

Post-revalidation note (2026-03-12): All seven attack phases have been independently corroborated by multiple sources following the March 9, 2026 public disclosure. The Google Cloud Threat Horizons Report H1 2026 serves as the authoritative primary source. Additional context from Unit 42's Slow Pisces research (April 2025) confirms the upstream tradecraft — fake coding challenges via LinkedIn deploying RN Loader/RN Stealer on macOS — used to initially compromise the developer. The $2.02B total DPRK crypto theft figure for 2025 (Chainalysis) and the FBI-attributed $1.5B ByBit heist (IC3 PSA, February 2025) place this breach within the context of an industrial-scale state-sponsored cryptocurrency theft campaign. OFAC and DOJ enforcement actions in late 2025 and early 2026 further confirm the TraderTraitor cluster as an active, high-priority threat to the cryptocurrency sector. No factual corrections to the original description are warranted.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1593 Search Open Websites/Domains
- T1587 Develop Capabilities
- T1583 Acquire Infrastructure
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1053 Scheduled Task/Job
- T1078 Valid Accounts
- T1611 Escape to Host
- T1036 Masquerading
- T1550 Use Alternate Authentication Material
- T1552 Unsecured Credentials
- T1528 Steal Application Access Token
- T1580 Cloud Infrastructure Discovery
- T1613 Container and Resource Discovery
- T1021 Remote Services
- T1530 Data from Cloud Storage
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1573 Encrypted Channel
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft
- T1565 Data Manipulation

## Sources

- [UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device](https://thehackernews.com/2026/03/unc4899-used-airdrop-file-transfer-and.html)
- [CISA Advisory AA22-108A: TraderTraitor — North Korean State-Sponsored APT Targets Blockchain Companies](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a)
- [TraderTraitor Deep Dive — Wiz Threat Research](https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist)
- [North Korea-Linked Hackers Target Crypto Supply Chain in Cloud Breach](https://www.cryptotimes.io/2026/03/09/north-korea-linked-hackers-target-crypto-supply-chain-in-cloud-breach/)
- [CISA AppleJeus Advisory AA21-048A](https://cisa.gov/uscert/ncas/alerts/aa21-048a)
- [Suspected DPRK Threat Actors Compromise Crypto Firms, Steal Keys and Cloud Assets](https://cybersecuritynews.com/suspected-dprk-threat-actors-compromise-crypto-firms/)
- [North Korean Hackers Using Fake Job Offers to Breach Cloud Systems](https://finance.yahoo.com/news/north-korean-hackers-using-fake-001623013.html)
- [Google Cloud, AWS Targeted by North Korean Hacking Group](https://www.scworld.com/brief/google-cloud-aws-targeted-by-north-korean-hacking-group)
- [From Digital Kleptocracy to Rogue Crypto-Superpower — 38 North Analysis](https://www.38north.org/2026/01/from-digital-kleptocracy-to-rogue-crypto-superpower/)
- [2025 Crypto Theft Reaches $3.4 Billion — Chainalysis](https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0202
