BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

North Korean Hackers Use Cloud, Social Lures in Crypto Heists

North Korean Hacking Group UNC4899 Breaches Google Cloud and AWS Using Social Engineering and Malicious Software Packages

  • North Korea-linked group UNC4899 used LinkedIn and Telegram to target employees at two organizations with social engineering attacks.
  • The attackers convinced employees to run malicious Docker containers, leading to breaches in Google Cloud and Amazon Web Services (AWS) environments.
  • UNC4899, also known as TraderTraitor and other names, has stolen millions of dollars in cryptocurrency, with incidents involving major heists from platforms like Axie Infinity, DMM Bitcoin, and Bybit.
  • The attackers bypassed security measures like multi-factor authentication and used stolen credentials and session cookies to access cloud resources and deploy Malware.
  • Security researchers report a rise in malware-filled npm and PyPI packages tied to North Korean groups, targeting developers and critical infrastructure.

North Korea-linked Hacking group UNC4899 targeted employees at two companies by contacting them through LinkedIn and Telegram. They posed as offering freelance software development opportunities to trick victims into running malicious Docker containers on their computers.

- Advertisement -

Google’s Cloud Threat Horizons Report for H2 2025 states that UNC4899 leveraged social engineering to breach cloud platforms used by these companies. The attackers accessed both Google Cloud and Amazon Web Services (AWS) environments, installing malware to compromise company resources and steal cryptocurrency.

The group, which also goes by TraderTraitor, Jade Sleet, PUKCHONG, and Slow Pisces, has been linked to past incidents like the Axie Infinity hack in March 2022 ($625 million), DMM Bitcoin in May 2024 ($308 million), and Bybit in February 2025 ($1.4 billion). According to Wiz, the group favors attacks where it targets customers of cloud platforms rather than the platforms themselves.

The campaign frequently relies on luring targets with job offers or requests to collaborate on developer platforms like npm and GitHub. Attackers often upload malicious npm packages and send them to employees, eventually leading to code execution on internal networks. Google noted that UNC4899 used stolen credentials for cloud access, disabled and then re-enabled multi-factor authentication (MFA) to hide its activities, and used long-term keys and session cookies to manage access.

During these attacks, Google found the attackers used admin permissions to replace legitimate JavaScript files with malicious code, which redirected cryptocurrency transactions to wallets under the attackers’ control. Both victims lost several million dollars as a result.

- Advertisement -

The report also highlights that Sonatype recently blocked 234 unique malware npm and PyPI packages linked to North Korea’s Lazarus Group. Many of these packages disguised themselves as standard developer tools but contained spyware capable of stealing secrets, capturing user profiles, and setting up persistent access to sensitive systems.

Security firms have observed an increase in malware activity within open source ecosystem registries during the first half of 2025, suggesting a shift by North Korean threat actors toward embedding malicious code directly in widely used software libraries.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

‘Godfather of Crypto’ Predicts Bitcoin Drop to $57K in 2026

Michael Terpin, an influential crypto investor, predicts the Bitcoin bull cycle peaked and will...

Kraken Urges US Tax Reforms After Filing 56M Forms

Kraken issued over 56 million tax forms to the IRS in 2025, with 18.5...

Harvester Deploys New Linux Backdoor in Espionage

The cyber-espionage group Harvester has deployed a new Linux variant of its GoGra backdoor...

Best Shiba Inu Buy Under $0.00001? Gains 6.5% Monthly

Shiba Inu (SHIB) has rallied 2.5% in the last 24 hours amid a wider...

Bitcoin Surging as Saylor Outpaces BlackRock; Musk Hint

Bitcoin surged nearly 30% from a low of $60,000 in early Q2 2026, approaching...

Must Read

Crypto in New York: The 2026 Guide to Legal Exchanges and BitLicense Regulations

TL;DR: Trading crypto in New York is legal but heavily regulated by the New York Department of Financial Services (NYDFS). Platforms must hold a BitLicense...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading