The North Korean threat group UNC4899 (also known as TraderTraitor) recently breached a cryptocurrency firm by exploiting a developer’s personal-to-corporate data transfer. The attack resulted in the theft of several million dollars in digital assets.
Breach Mechanism: The AirDrop Vector
The intrusion began when a developer at the target firm used AirDrop to transfer a trojanized archive from a personal device to their corporate work machine.
- Trojanized File: The archive contained a malicious file disguised as a legitimate Kubernetes CLI tool.
- Initial Execution: Once launched on the work device, the file opened a backdoor that allowed the attackers to establish persistent access.
Escalation and Theft Chain
After gaining a foothold on the developer’s machine, the attackers pivoted into the firm’s cloud infrastructure:
- Privilege Escalation: UNC4899 obtained tokens for a high-privileged CI/CD service account, allowing them to move laterally.
- Infrastructure Access: The attackers targeted a sensitive infrastructure pod running in privileged mode, escaping the container to deepen their access.
- Database Compromise: They extracted static database credentials stored in environment variables, used to access the production database via Cloud SQL Auth Proxy.
- Account Manipulation: Using SQL commands, the threat actors reset passwords and updated MFA seeds for high-value user accounts.
- Exfiltration: The breach culminated in the unauthorized withdrawal of millions of dollars in cryptocurrency.
Threat Actor Context
UNC4899 is identified as a cryptocurrency-focused element of North Korea’s Reconnaissance General Bureau (RGB). The group is known for:
- Social Engineering: Frequently using fake job lures on LinkedIn or Telegram to trick developers into running malicious code.
- Advanced Backdoors: Utilizing modular backdoors like FULLHOUSE.DOORED, STRATOFEAR, and TIEDYE.
- Supply Chain Attacks: Previously targeting SaaS providers like JumpCloud to reach downstream customers.