Jade Sleet

Threat Actor Profile Updated a month ago
Download STIX
Preview STIX
Jade Sleet, also known as TraderTraitor and UNC4899, is a North Korean state-sponsored threat actor primarily targeting personal GitHub user accounts connected to the blockchain, cryptocurrency, and online gambling sectors. Their activities support Pyongyang's objectives, with GitHub expressing "high confidence" in their involvement. The group has been implicated in various cyber attacks, including the JumpCloud hack, and has been attributed by Microsoft and CISA as the driving force behind these malicious activities. They differentiate themselves from other threat actors such as Lazarus (Moonstone Sleet) through unique structures and styles of their malicious code packages. In July 2023, GitHub disclosed details of an npm campaign where Jade Sleet used fake personas to target the cybersecurity sector among others. This was part of a broader social engineering spear-phishing campaign that targeted employees of cryptocurrency and technology organizations. The attackers utilized GitHub repos and weaponized npm packages, often impersonating developers or recruiters. In some instances, they created false persona accounts on platforms like GitHub, LinkedIn, Slack, and Telegram, while in others, they took control of legitimate accounts. The FBI has attributed the blockchain activity to Jade Sleet, confirming their focus on users and vendors associated with cryptocurrency and other blockchain-related organizations. The threat posed by this group extends beyond direct targets, affecting the broader cybersecurity landscape due to their sophisticated attack methods and state sponsorship. It is critical for organizations, especially those operating within Jade Sleet's primary target sectors, to remain vigilant against such threats and implement robust security measures to safeguard their digital assets.
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Unc4899
1
UNC4899, also known as TraderTraitor and Jade Sleet, is a threat actor identified by Google's Mandiant as a North Korean hacking group with a focus on cryptocurrency-related activities. The group operates under the auspices of North Korea's Reconnaissance General Bureau (RGB) and primarily targets b
Tradertraitor
1
TraderTraitor, also known as Lazarus Group or APT38, is a threat actor attributed to the North Korean government. This group has been linked by the FBI to several recent cyberattacks on cryptocurrency platforms, with hundreds of millions of dollars in cryptocurrency stolen. The attacks share similar
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Korean
Github
State Sponso...
Phishing
Telegram
Associated Malware
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Associated Threat Actors
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Associated Vulnerabilities
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Source Document References
Information about the Jade Sleet Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
SourceCreatedAtTitle
DARKReading
a month ago
North Korea's Moonstone Sleet Widens Distribution of Malicious Code
DARKReading
2 months ago
Asian Threat Actors Use New Techniques to Attack Familiar Targets
CERT-EU
8 months ago
North Korean Hackers Pose as Job Recruiters and Seekers in Malware Campaigns
CERT-EU
a year ago
North Korean Cyberspies Target GitHub Developers
CERT-EU
a year ago
North Korean Hackers Exploit Zero-Day Bug to Target Cybersecurity Researchers
CERT-EU
a year ago
North Korean Affiliates Suspected in $40M Cryptocurrency Heist, FBI Warns
BankInfoSecurity
a year ago
JumpCloud Hackers Likely Targeting GitHub Accounts Too
CERT-EU
a year ago
Cyber Security Week In Review: July 21, 2023
CERT-EU
a year ago
GitHub Warns of North Korean Social Engineering Attacks Targeting Tech Firm Employees
CERT-EU
a year ago
GitHub Developers Targeted by North Korea’s Lazarus Group
CERT-EU
a year ago
GitHub Warns of North Korean Social Engineering Attacks Targeting Tech Firm Employees