UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device

In order to steal millions of dollars in bitcoin, a sophisticated cloud hack campaign targeting a cryptocurrency company in 2025 is alleged to have been carried out by the North Korean threat actor known as UNC4899.

The state-sponsored adversary, also known as the cryptonyms Jade Sleet, PUKCHONG, Slow Pisces, and TraderTraitor, has been identified with intermediate confidence as the source of the activity.

According to the tech giant’s H1 2026 Cloud Threat Horizons Report, which was shared with The Hacker News, this incident is noteworthy for its combination of social engineering, exploitation of personal-to-corporate device peer-to-peer data (P2P) transfer mechanisms, workflows, and eventual pivot to the cloud to use living-off-the-cloud (LOTC) techniques.

After getting access to the cloud environment, the attackers are alleged to have tampered with Cloud SQL databases to enable bitcoin theft read more about UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *