Image for Article: UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device

Article Details

Title
Article: UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device
Impact Score
6 / 10
AI Summary (Processed Content)

A North Korean threat actor, UNC4899, compromised a cryptocurrency organization in 2025 to steal millions. The attack began with social engineering against a developer, leading to the compromise of a corporate device and a pivot to the cloud. Using living-off-the-cloud techniques, the attackers abused DevOps workflows, escalated privileges in Kubernetes, and tampered with a Cloud SQL database to alter high-value user accounts and facilitate the theft.

Original URL
https://thehackernews.com/2026/03/unc4899-used-airdrop-file-transfer-and.html
Source Feed
The Hacker News
Published Date
2026-03-09 14:50
Fetched Date
2026-03-09 13:45
Processed Date
2026-03-09 13:45
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content