logo

UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device

ID: 49e6407f-d447-56a7-8397-94f3ba0250b6

STIX ID: report--49e6407f-d447-56a7-8397-94f3ba0250b6

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A sophisticated 2025 cloud compromise attributed to UNC4899 used social engineering and personal-to-corporate P2P file transfer to infect a developer, enabling a pivot to Google Cloud where the adversary abused DevOps workflows and Kubernetes (including privileged containers and injected deployments) to harvest service-account tokens, escape containers, obtain database credentials, alter Cloud SQL records (passwords/MFA seeds), and steal millions of dollars in cryptocurrency; the report emphasizes LOTC techniques and recommends phishing-resistant MFA, secrets management, runtime isolation, and restrictions on P2P sharing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.