Google’s H1 2026 Cloud Threat Horizons reporting described a sophisticated intrusion attributed with moderate confidence to North Korea-linked UNC4899 (aka Jade Sleet, PUKCHONG, Slow Pisces, TraderTraitor) that targeted a cryptocurrency organization in 2025 and resulted in the theft of millions in cryptocurrency. The attack began with social engineering against a developer, who downloaded a malicious archive under the guise of open-source collaboration and then transferred it from a personal device to a corporate workstation via AirDrop; interaction with the archive led to execution of malicious Python that launched a backdoor binary masquerading as the Kubernetes CLI (kubectl). From the compromised endpoint, the actor pivoted into the cloud environment and used living-off-the-cloud (LOTC) techniques, abusing legitimate DevOps workflows to harvest credentials, escape container boundaries, and tamper with Cloud SQL databases to alter financial logic and enable theft.
Separately, Google’s broader cloud incident trend analysis found attackers are increasingly using newly disclosed third-party vulnerabilities—not just weak credentials or misconfigurations—for initial access into cloud environments, with exploit “time-to-weaponization” shrinking from weeks to days (including cryptominer deployment within ~48 hours of disclosure). In Google’s reviewed intrusions, vulnerability exploitation was the leading initial access vector (44.5%) versus credentials (27%), with RCE flaws most frequently abused; examples cited include React2Shell (CVE-2025-55182) and an XWiki vulnerability (CVE-2025-24893) used in RondoDox botnet activity. The report also noted continued use of compromised identities via phishing/vishing (often help desk impersonation) and that many cloud intrusions prioritized quiet, high-volume data exfiltration and persistence over immediate extortion.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In March 2026, Google Cloud released its Cloud Threat Horizons Report H1 2026 summarizing H2 2025 trends, including the rise of software-exploit-driven cloud attacks, insider data exfiltration, supply-chain abuse of GitHub-to-cloud OIDC trust, and North Korean activity such as UNC4899’s multimillion-dollar crypto theft. The report framed these findings as evidence that cloud attacks are accelerating and increasingly require automated, defense-in-depth responses.
Across the second half of 2025, Google observed that exploitation of third-party software vulnerabilities became the leading initial access vector in cloud compromises, accounting for 44.5% of incidents and surpassing credential-based access. Attackers increasingly weaponized newly disclosed flaws within days, often using remote code execution vulnerabilities such as React2Shell and an XWiki flaw.
Later in the same 2025 campaign, the attackers extracted insecurely stored database credentials, accessed production databases through Cloud SQL Auth Proxy, and modified user accounts by resetting passwords and updating MFA seeds. The operation culminated in withdrawals of several million dollars in cryptocurrency from the victim organization.
After initial access, UNC4899 used a Kubernetes-themed backdoor and existing sessions or credentials to move into the victim’s Google Cloud environment. The attackers modified MFA-related settings, altered Kubernetes deployments and CI/CD resources, exposed service account tokens in logs, escalated privileges, and maintained persistent access.
In 2025, a North Korean-linked actor later attributed as UNC4899 tricked a developer at a cryptocurrency organization into downloading a malicious archive on a personal device, which was then transferred via AirDrop to a corporate device and executed. The intrusion gave the attackers an initial foothold in the victim’s environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcedarkreading.com
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.