Tag: Korean Hackers

N. Korean Hackers Used Job Lures, Cloud Account Access, and Malware to Steal Millions in Crypto
News

N. Korean Hackers Used Job Lures, Cloud Account Access, and Malware to Steal Millions in Crypto

UNC4899, a threat actor associated with North Korea, has been implicated in attacks that targeted two distinct firms by contacting their employees using Telegram and LinkedIn. Google's cloud division stated [PDF] in its Cloud Threat Horizons Report for H2 2025 that UNC4899 used social engineering techniques to successfully persuade the targeted employees to run malicious Docker containers on their workstations under the pretense of freelance opportunities for software development work. Activity monitored under the names Jade Sleet, PUKCHONG, Slow Pisces, and TraderTraitor coincides with UNC4899. The state-sponsored actor has been active since at least 2020 and is well-known for focusing on the blockchain and cryptocurrency sectors. Significant cryptocurrency heists, such as those...