UNC4899 is a designation Mandiant uses for a Democratic People's Republic of Korea-nexus threat actor that Mandiant assesses, with high confidence, functions as a cryptocurrency-focused element within North Korea's Reconnaissance General Bureau, and which Mandiant believes likely corresponds to the actor publicly reported as TraderTraitor. Mandiant first disclosed the designation in connection with a July 2023 supply-chain compromise in which the actor gained initial access to a software solutions company by compromising the JumpCloud identity and access management platform, deploying a malicious Ruby script through JumpCloud's agent to reach downstream customer systems. The intrusion involved macOS backdoors that Mandiant named FULLHOUSE.DOORED and STRATOFEAR, deployed within 24 hours of initial access and disguised as legitimate applications such as Docker and Zoom components. In subsequent reporting, Mandiant grouped UNC4899 with a related cluster, UNC4736, behind the 3CX and Trading Technologies supply-chain attacks, describing both as sophisticated, consistent operations that use trusted software providers to gain broad downstream network access.
JumpCloud
#JumpCloud • 2023-06
🇺🇸 United States
JumpCloud disclosed a targeted compromise of internal infrastructure after a spear-phishing campaign, with anomalous activity in its commands framework affecting a small set of customers and forcing credential rotation, infrastructure rebuilds, and customer admin API key resets. Mandiant attributed related intrusions to UNC4899, a DPRK-nexus actor with cryptocurrency-sector targeting history, and other reporting linked attacker infrastructure, malicious npm packages, and supply-chain targeting patterns to North Korean state-sponsored activity.
-
12
Related Reports
-
1
Affected Countries
-
38
Months Since
Related Actors
Associated with: Trader Traitor
First seen: 2023-07 •
Last seen: 2026-07
Related Reports
2024-03-07
UN