A recent report from DeFi protocol Radiant Capital reveals that the $50 million exploit it experienced in October has been linked to hackers from North Korea. According to the report, published on December 6, the groundwork for the October 16 attack was laid as early as mid-September.
This was when a Telegram message, purportedly from a trusted former contractor, was sent to a Radiant Capital developer. The message mentioned a new career opportunity related to smart contract auditing and requested feedback, including a link to a zipped PDF file. The developer, unaware of the malicious intent, opened the file and shared it with colleagues. The report now suggests that the message was sent by a 'DPRK-aligned threat actor' impersonating the contractor.
The PDF file contained malware known as INLETDRIFT, which created a persistent backdoor on macOS systems while displaying a legitimate-looking PDF to the user. Radiant Capital noted that standard checks and simulations did not reveal any obvious discrepancies, making the threat nearly undetectable during regular review processes. By gaining access to the computers, the hackers were able to obtain control of multiple private keys. The connection to North Korea was identified by cybersecurity firm Mandiant, although the investigation remains ongoing.
Mandiant believes the attack was carried out by UNC4736, a group associated with North Korea's Reconnaissance General Bureau, also known as AppleJeus or Citrine Sleet. This group has been implicated in several other attacks targeting cryptocurrency companies, often using fake cryptocurrency exchange websites to trick individuals into downloading malicious software through links to job openings and fake wallets. This incident follows an earlier, unrelated hacking incident against Radiant Capital in January, which resulted in a loss of $4.5 million.