Citrine Sleet / AppleJeus
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3k4L7q…w1RLSummary
Citrine Sleet (also tracked as AppleJeus, Gleaming Pisces, UNC4736, and Labyrinth Chollima) is a North Korean state-sponsored threat cluster attributed to Bureau 121 of the Reconnaissance General Bureau (RGB), active since at least 2018. The group specializes in financially motivated cyberattacks against cryptocurrency exchanges, DeFi protocols, and developer toolchains, deploying trojanized trading applications, supply chain compromises, and zero-day exploits to steal digital assets. Chainalysis estimates DPRK-linked actors have stolen at least $6.75 billion in cryptocurrency since 2016, with Citrine Sleet/UNC4736 operations accounting for multiple hundred-million-dollar individual incidents including the April 2026 Drift Protocol exploit ($285 million) and the October 2024 Radiant Capital breach ($50 million).
Connected Entities
1 entities- + 12 more
Timeline(22 events)
June 2018
AppleJeus malware samples dated June–August 2018 deployed against a cryptocurrency exchange in Asia via trojanized 'Celas Trade Pro' application from fake company 'Celas LLC.' First documented macOS malware deployment by Lazarus Group.
Kaspersky Lab Securelist23 August 2018
Kaspersky Lab publicly discloses Operation AppleJeus, attributing trojanized cryptocurrency trading software to the Lazarus Group.
Business Wire / Kaspersky13 September 2019
OFAC formally sanctions the Lazarus Group as an agency or instrumentality of the Government of the DPRK.
U.S. Department of the Treasury17 February 2021
CISA, FBI, and the Department of the Treasury issue joint advisory AA21-048A documenting seven AppleJeus malware variants and associated fake cryptocurrency trading companies targeting organizations in over 30 countries.
CISAFebruary 2022
Trading Technologies website compromised via hidden IFRAME exploit (CVE-2022-0609); X_TRADER software trojanized with VEILEDSIGNAL backdoor, initiating the 3CX supply chain attack chain.
Mandiant / Google Cloud BlogDecember 2022
Volexity documents additional AppleJeus variants including 'BloxHolder' fake trading platform distributing updated malware.
VolexityMarch 2023
3CX DesktopApp supply chain compromise discovered; malicious versions 18.12.416 and earlier found to deliver SUDDENICON and ICONICSTEALER to enterprise users globally.
3CX / Mandiant20 April 2023
Mandiant publishes full 3CX supply chain compromise analysis, attributing the cascading attack to UNC4736 with high confidence of North Korean nexus.
Mandiant / Google Cloud BlogFebruary 2024
Malicious Python packages (real-ids, coloredtxt, beautifultext, minisound) containing PondRAT backdoor uploaded to PyPI, attributed to Gleaming Pisces (Citrine Sleet) by Palo Alto Networks Unit 42.
Palo Alto Networks Unit 4213 August 2024
Microsoft patches CVE-2024-38106 (Windows kernel vulnerability) as part of August Patch Tuesday.
Microsoft19 August 2024
Microsoft identifies Citrine Sleet actively exploiting Chromium zero-day CVE-2024-7971 (V8 type confusion, CVSS 8.8) to deliver FudModule rootkit via exploit domain voyagorclub[.]space.
Microsoft Security Blog30 August 2024
Microsoft publicly publishes Citrine Sleet CVE-2024-7971 / FudModule rootkit analysis.
Microsoft Security Blog11 September 2024
UNC4736 operatives send malicious ZIP file via Telegram to Radiant Capital developers, impersonating a former contractor and delivering INLETDRIFT macOS backdoor inside a PDF.
CoinTelegraphSeptember 2024
Palo Alto Networks Unit 42 publishes Gleaming Pisces / PondRAT poisoned Python packages campaign analysis.
Palo Alto Networks Unit 4216 October 2024
UNC4736 (Citrine Sleet) exploits compromised Radiant Capital developer devices to drain approximately $50 million from the cross-chain DeFi protocol. Three developers' multisig keys are used to approve fraudulent transactions.
CoinDesk9 December 2024
Radiant Capital publicly attributes the October 2024 $50 million exploit to UNC4736 (Citrine Sleet) following Mandiant investigation.
CoinDeskOctober 2025
Citrine Sleet operatives begin approaching Drift Protocol contributors at major cryptocurrency conferences, presenting as employees of a quantitative trading firm. Six-month social engineering operation commences.
The Hacker NewsDecember 2025
Attackers onboard an Ecosystem Vault on Drift Protocol, depositing over $1 million in real capital to establish legitimacy and begin formal integration discussions.
CoinDeskFebruary 2026
Drift operatives continue in-person meetings with contributors across multiple countries, sharing malicious links and ultimately compromising contributor devices via malicious VSCode project (tasks.json exploit) and a TestFlight iOS application.
The RecordApril 2026
Attackers execute durable nonce attack on Drift Protocol using pre-signed multisig transactions dormant for over one week, draining approximately $285 million in user assets in roughly twelve minutes. Telegram channels and malware are immediately deleted.
Bleeping Computer5 April 2026
Drift Protocol publishes post-mortem attributing attack to UNC4736 (Citrine Sleet) with medium confidence based on on-chain fund flows to Radiant Capital addresses. Mandiant and law enforcement engaged.
CoinDeskDecision Log
- hash: 38m11vnHfvGxLb1mJTVudbyny26DTepuwqSZhRLzf5c5
- hash: Dx38ddX7HEXgupnJniMo9zVNxzbZMB6fyzXQUw59vDZm
- hash: AKG4ES5XgqdMkkDjjiagxked4b4JLyYG7fpb5zsA5n3k
This investigation is cryptographically anchored to the Solana blockchain (3 events). 24 of 24 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 6/3/2026, 12:08:13 AM
last updated: 7/26/2026, 4:25:42 PM
avoid.net — verified advice for a post-truth world