UNC4736
2023-04-11 • Mandiant • Security Update Mandiant Initial Results
Mandiant assigned the cluster designator UNC4736 during its 2023 response to the 3CX Desktop App supply-chain compromise, assessing with high confidence a North Korean nexus and, with moderate confidence, overlap with financially motivated AppleJeus activity, also tracked as Citrine Sleet. Mandiant traced the intrusion to an earlier compromise of Trading Technologies' X_TRADER installer, trojanized with the VEILEDSIGNAL backdoor, which let the actor steal an employee's corporate credentials, move laterally using a renamed Fast Reverse Proxy tool, and compromise 3CX's Windows and macOS build environments using TAXHAUL/COLDCAT and the POOLRAT backdoor, ultimately trojanizing the 3CX app with a SUDDENICON downloader and ICONICSTEALER data miner. Mandiant later attributed the October 2024 theft of roughly $50 million from DeFi platform Radiant Capital to the cluster after developers were lured via Telegram into opening a fake PDF report that deployed the INLETDRIFT macOS backdoor and enabled manipulation of signed transactions. Subsequent researchers linked the April 2026 Drift Protocol exploit and a memory-resident RemotePE malware chain used in financial-espionage intrusions to the same cluster, described as aligned with North Korea's Reconnaissance General Bureau.
-
60
Related Actors
-
690
Related Reports