logo

North Korean hackers behind $50 million crypto heist of Radiant Capital

ID: bf848b46-38bf-5984-b880-8e63ce503113

STIX ID: report--bf848b46-38bf-5984-b880-8e63ce503113

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2024-12-11

Date Updated: 2026-05-01

...
...

Radiant Capital was compromised after engineers received a ZIP containing a PDF that deployed the INLETDRIFT macOS backdoor; the activity is attributed to North Korean APT AppleJeus/Citrine Sleet and resulted in theft of more than $50M. The attack used social engineering and a malicious document that masked malicious transactions behind benign front-end displays, demonstrating high sophistication and supply-chain targeting; Radiant engaged Mandiant and law enforcement to investigate and recover assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.