Cyber Hacking NewsCyber Security

North Korean Hackers steal $50 M in Crypto from Radiant Capital

0

Radiant Capital has confirmed that North Korean hackers were behind the $50 million cryptocurrency heist following a cyberattack on October 16, 2024. 

The breach was traced to a sophisticated malware attack orchestrated by a group identified as Citrine Sleet, also known as UNC4736 or AppleJeus. This cybercrime targeted the decentralized finance (DeFi) platform, which provides multi-chain cryptocurrency services, including lending and borrowing.

The attack occurred after hackers compromised the devices of three trusted Radiant developers. The malicious activity bypassed the platform’s advanced security systems, including hardware wallets and multi-step transaction verification, allowing hackers to execute unauthorized transfers from the Arbitrum and Binance Smart Chain (BSC) markets without raising alarms.

Radiant initially reported the breach on October 16, noting that the hackers had exploited the routine multi-signature process, collecting valid transaction signatures while masquerading as errors in the process. Despite the sophisticated nature of the attack, transactions appeared normal during manual and automated checks.

Following an internal investigation, Radiant collaborated with cybersecurity experts at Mandiant, who confirmed that the attackers were part of the North Korean hacking group UNC4736. This group has previously been implicated in several high-profile cyberattacks, including exploiting a zero-day vulnerability in Google Chrome earlier this year.

The attack was initiated on September 11, 2024, when one of Radiant’s developers received a fraudulent Telegram message disguised as a communication from a former contractor. The message tricked the developer into downloading a ZIP file containing a malicious PDF that concealed the ‘InletDrift’ macOS malware. This malware established a backdoor on the compromised devices, allowing the attackers to proceed with the theft.

Radiant noted that the attack was so carefully executed that even with the platform’s strict security practices—such as transaction simulations and data verification—the malicious activity went undetected until after the funds were stolen. The attackers’ actions were virtually invisible during the normal review stages, making the heist difficult to identify.

Radiant Capital is working with U.S. law enforcement agencies and cybersecurity firm zeroShadow to trace and recover the stolen funds. The platform has also underscored the importance of improving device-level security measures to prevent similar incidents in the future.

This breach highlights the ongoing threat posed by North Korean hackers, who have been increasingly targeting cryptocurrency exchanges and platforms as a means to generate and launder funds to support the country’s operations.

Image Credit : The Crypto Times

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Russia sentences Hydra Dark Web Leader to life in Prison

Previous article

Clop Ransomware claims responsibility for Cleo Data Breaches

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *