Radiant Capital Incident Update

2024-12-06 Radiant Capital

https://medium.com/@RadiantCapital/radiant-capital-incident-update-e56d8c23829e

Radiant Capital reports that a September 2024 Telegram lure impersonated a trusted former contractor and delivered a zipped file that was later shared among developers for review. The ZIP contained INLETDRIFT, a macOS backdoor packaged as a legitimate-looking PDF application, using AppleScript to communicate with atokyonews[.]com and establish persistence. The attackers compromised multiple developer devices, staged malicious smart contracts across several chains, and caused front-end interfaces to display benign transaction data while malicious transactions were signed in the background. Mandiant attributed the attack with high confidence to UNC4736, also known as AppleJeus or Citrine Sleet, assessed as a DPRK-nexus actor aligned with the Reconnaissance General Bureau.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN atokyonews.com 2024-12-06 2024-12-20
HASH ff15427d45b84e79b2e81199613041bb 2024-12-06 2024-12-06
URL https://atokyonews.com/CloudChe… 2024-12-06 2024-12-06

Related Actors

Related Reports

« Back