Crypto Firm Hacked After Developer AirDrops Trojanized File
Mar 9, 2026 // 19:53 - Norina Velotta


The North Korean threat group UNC4899 (also known as TraderTraitor) recently breached a cryptocurrency firm by exploiting a developer’s personal-to-corporate data transfer. The attack resulted in the theft of several million dollars in digital assets.

Breach Mechanism: The AirDrop Vector

The intrusion began when a developer at the target firm used AirDrop to transfer a trojanized archive from a personal device to their corporate work machine.

  • Trojanized File: The archive contained a malicious file disguised as a legitimate Kubernetes CLI tool.
  • Initial Execution: Once launched on the work device, the file opened a backdoor that allowed the attackers to establish persistent access.

Escalation and Theft Chain

After gaining a foothold on the developer’s machine, the attackers pivoted into the firm’s cloud infrastructure:

  • Privilege Escalation: UNC4899 obtained tokens for a high-privileged CI/CD service account, allowing them to move laterally.
  • Infrastructure Access: The attackers targeted a sensitive infrastructure pod running in privileged mode, escaping the container to deepen their access.
  • Database Compromise: They extracted static database credentials stored in environment variables, used to access the production database via Cloud SQL Auth Proxy.
  • Account Manipulation: Using SQL commands, the threat actors reset passwords and updated MFA seeds for high-value user accounts.
  • Exfiltration: The breach culminated in the unauthorized withdrawal of millions of dollars in cryptocurrency.

Threat Actor Context

UNC4899 is identified as a cryptocurrency-focused element of North Korea’s Reconnaissance General Bureau (RGB). The group is known for:

  • Social Engineering: Frequently using fake job lures on LinkedIn or Telegram to trick developers into running malicious code.
  • Advanced Backdoors: Utilizing modular backdoors like FULLHOUSE.DOORED, STRATOFEAR, and TIEDYE.
  • Supply Chain Attacks: Previously targeting SaaS providers like JumpCloud to reach downstream customers.

#after  #airdrops  #crypto  #developer  #file  #firm  #hacked  #news  #trojanized   —   News