Citrine Sleet being the first activity group Microsoft observed capitalizing on a prior supply chain compromise to conduct the 3CX supply chain attack in March 2023
Radiant Capital
#RadiantCapital • 2024-10
🇭🇰 Hong Kong
In October 2024, Radiant Capital lost more than $53 million after attackers compromised multiple developer devices and manipulated multisig transaction signing. Radiant later said the operation began with a September 2024 Telegram lure impersonating a trusted former contractor, delivered the INLETDRIFT macOS backdoor, and caused front-end interfaces to show benign transaction data while malicious transactions were signed in the background; Mandiant attributed the activity to DPRK-nexus UNC4736/AppleJeus/Citrine Sleet.
-
12
Related Reports
-
1
Affected Countries
-
20
Months Since
Related Actors
Associated with: Apple Jeus
First seen: 2022-12 •
Last seen: 2026-05