UNC4899 is a designation Mandiant uses for a Democratic People's Republic of Korea-nexus threat actor that Mandiant assesses, with high confidence, functions as a cryptocurrency-focused element within North Korea's Reconnaissance General Bureau, and which Mandiant believes likely corresponds to the actor publicly reported as TraderTraitor. Mandiant first disclosed the designation in connection with a July 2023 supply-chain compromise in which the actor gained initial access to a software solutions company by compromising the JumpCloud identity and access management platform, deploying a malicious Ruby script through JumpCloud's agent to reach downstream customer systems. The intrusion involved macOS backdoors that Mandiant named FULLHOUSE.DOORED and STRATOFEAR, deployed within 24 hours of initial access and disguised as legitimate applications such as Docker and Zoom components. In subsequent reporting, Mandiant grouped UNC4899 with a related cluster, UNC4736, behind the 3CX and Trading Technologies supply-chain attacks, describing both as sophisticated, consistent operations that use trusted software providers to gain broad downstream network access.
Woo X
#WooX • 2025-07
🇺🇸 United States
On July 24, 2025, WOO X suffered a cryptocurrency-theft incident attributed by the exchange to suspected North Korea-linked activity. A developer ran a malicious open-source collaboration project on a company MacBook, giving the actor access through a compromised VPN session into cloud and Kubernetes infrastructure; the actor later changed credentials for nine high-value accounts and initiated about $14 million in unauthorized withdrawals across multiple chains.
-
2
Related Reports
-
1
Affected Countries
-
13
Months Since
Related Actors
Associated with: Trader Traitor
First seen: 2023-07 •
Last seen: 2026-07