Radiant Capital Incident Update
2024-12-06 • Radiant Capital •
https://medium.com/@RadiantCapital/radiant-capital-incident-update-e56d8c23829e
Radiant Capital reports that a September 2024 Telegram lure impersonated a trusted former contractor and delivered a zipped file that was later shared among developers for review. The ZIP contained INLETDRIFT, a macOS backdoor packaged as a legitimate-looking PDF application, using AppleScript to communicate with atokyonews[.]com and establish persistence. The attackers compromised multiple developer devices, staged malicious smart contracts across several chains, and caused front-end interfaces to display benign transaction data while malicious transactions were signed in the background. Mandiant attributed the attack with high confidence to UNC4736, also known as AppleJeus or Citrine Sleet, assessed as a DPRK-nexus actor aligned with the Reconnaissance General Bureau.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | atokyonews.com | 2024-12-06 | 2024-12-20 |
| HASH | ff15427d45b84e79b2e81199613041bb | 2024-12-06 | 2024-12-06 |
| URL | https://atokyonews.com/CloudChe… | 2024-12-06 | 2024-12-06 |