Associated with: Trader Traitor
First seen: 2023-07 •
Last seen: 2026-03
#JumpCloud • 2023-06
JumpCloud disclosed a targeted compromise of internal infrastructure after a spear-phishing campaign, with anomalous activity in its commands framework affecting a small set of customers and forcing credential rotation, infrastructure rebuilds, and customer admin API key resets. Mandiant attributed related intrusions to UNC4899, a DPRK-nexus actor with cryptocurrency-sector targeting history, and other reporting linked attacker infrastructure, malicious npm packages, and supply-chain targeting patterns to North Korean state-sponsored activity.
12
Related Reports
1
Affected Countries
36
Months Since