UNC4899 Breaches Cryptocurrency Firm via Trojans

A North Korean hacking group is linked to a major breach of a cryptocurrency firm, utilizing airdropped malware to infiltrate systems.

3 min readCybersecurity

In 2025, a significant breach occurred at a cryptocurrency firm, attributed to the North Korean cyber group known as UNC4899. This group, which operates under various aliases including Jade Sleet and Slow Pisces, executed a sophisticated attack that involved a developer inadvertently transferring a compromised file to their work device via AirDrop. This method allowed the attackers to bypass traditional security measures and gain access to sensitive information. The breach is believed to have resulted in the theft of millions in cryptocurrency, highlighting the vulnerabilities within the digital asset sector. Experts emphasize the need for enhanced security protocols to protect against such targeted attacks, especially as cyber threats continue to evolve. The incident serves as a stark reminder of the risks associated with remote work and the importance of vigilance in cybersecurity practices.

Cybersecurity