Citrine Sleet / AppleJeus
Summary
Citrine Sleet (also tracked as AppleJeus, Gleaming Pisces, UNC4736, and Labyrinth Chollima) is a North Korean state-sponsored threat cluster attributed to Bureau 121 of the Reconnaissance General Bureau (RGB), active since at least 2018. The group specializes in financially motivated cyberattacks against cryptocurrency exchanges, DeFi protocols, and developer toolchains, deploying trojanized trading applications, supply chain compromises, and zero-day exploits to steal digital assets. Chainalysis estimates DPRK-linked actors have stolen at least $6.75 billion in cryptocurrency since 2016, with Citrine Sleet/UNC4736 operations accounting for multiple hundred-million-dollar individual incidents including the April 2026 Drift Protocol exploit ($285 million) and the October 2024 Radiant Capital breach ($50 million).
Connected Entities
1 entities · 10 linked investigations- + 12 more
Timeline(22 events)
2018-06-01
AppleJeus malware samples dated June–August 2018 deployed against a cryptocurrency exchange in Asia via trojanized 'Celas Trade Pro' application from fake company 'Celas LLC.' First documented macOS malware deployment by Lazarus Group.
Kaspersky Lab Securelist2018-08-23
Kaspersky Lab publicly discloses Operation AppleJeus, attributing trojanized cryptocurrency trading software to the Lazarus Group.
Business Wire / Kaspersky2019-09-13
OFAC formally sanctions the Lazarus Group as an agency or instrumentality of the Government of the DPRK.
U.S. Department of the Treasury2021-02-17
CISA, FBI, and the Department of the Treasury issue joint advisory AA21-048A documenting seven AppleJeus malware variants and associated fake cryptocurrency trading companies targeting organizations in over 30 countries.
CISA2022-02-01
Trading Technologies website compromised via hidden IFRAME exploit (CVE-2022-0609); X_TRADER software trojanized with VEILEDSIGNAL backdoor, initiating the 3CX supply chain attack chain.
Mandiant / Google Cloud Blog2022-12-01
Volexity documents additional AppleJeus variants including 'BloxHolder' fake trading platform distributing updated malware.
Volexity2023-03-01
3CX DesktopApp supply chain compromise discovered; malicious versions 18.12.416 and earlier found to deliver SUDDENICON and ICONICSTEALER to enterprise users globally.
3CX / Mandiant2023-04-20
Mandiant publishes full 3CX supply chain compromise analysis, attributing the cascading attack to UNC4736 with high confidence of North Korean nexus.
Mandiant / Google Cloud Blog2024-02-01
Malicious Python packages (real-ids, coloredtxt, beautifultext, minisound) containing PondRAT backdoor uploaded to PyPI, attributed to Gleaming Pisces (Citrine Sleet) by Palo Alto Networks Unit 42.
Palo Alto Networks Unit 422024-08-13
Microsoft patches CVE-2024-38106 (Windows kernel vulnerability) as part of August Patch Tuesday.
Microsoft2024-08-19
Microsoft identifies Citrine Sleet actively exploiting Chromium zero-day CVE-2024-7971 (V8 type confusion, CVSS 8.8) to deliver FudModule rootkit via exploit domain voyagorclub[.]space.
Microsoft Security Blog2024-08-30
Microsoft publicly publishes Citrine Sleet CVE-2024-7971 / FudModule rootkit analysis.
Microsoft Security Blog2024-09-11
UNC4736 operatives send malicious ZIP file via Telegram to Radiant Capital developers, impersonating a former contractor and delivering INLETDRIFT macOS backdoor inside a PDF.
CoinTelegraph2024-09-01
Palo Alto Networks Unit 42 publishes Gleaming Pisces / PondRAT poisoned Python packages campaign analysis.
Palo Alto Networks Unit 422024-10-16
UNC4736 (Citrine Sleet) exploits compromised Radiant Capital developer devices to drain approximately $50 million from the cross-chain DeFi protocol. Three developers' multisig keys are used to approve fraudulent transactions.
CoinDesk2024-12-09
Radiant Capital publicly attributes the October 2024 $50 million exploit to UNC4736 (Citrine Sleet) following Mandiant investigation.
CoinDesk2025-10-01
Citrine Sleet operatives begin approaching Drift Protocol contributors at major cryptocurrency conferences, presenting as employees of a quantitative trading firm. Six-month social engineering operation commences.
The Hacker News2025-12-01
Attackers onboard an Ecosystem Vault on Drift Protocol, depositing over $1 million in real capital to establish legitimacy and begin formal integration discussions.
CoinDesk2026-02-01
Drift operatives continue in-person meetings with contributors across multiple countries, sharing malicious links and ultimately compromising contributor devices via malicious VSCode project (tasks.json exploit) and a TestFlight iOS application.
The Record2026-04-01
Attackers execute durable nonce attack on Drift Protocol using pre-signed multisig transactions dormant for over one week, draining approximately $285 million in user assets in roughly twelve minutes. Telegram channels and malware are immediately deleted.
Bleeping Computer2026-04-05
Drift Protocol publishes post-mortem attributing attack to UNC4736 (Citrine Sleet) with medium confidence based on on-chain fund flows to Radiant Capital addresses. Mandiant and law enforcement engaged.
CoinDeskDecision Log
- hash: AKG4ES5XgqdMkkDjjiagxked4b4JLyYG7fpb5zsA5n3k
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-code-investigator
generated: 6/3/2026, 12:08:13 AM
last updated: 6/3/2026, 12:08:19 AM
avoid.net — verified advice for a post-truth world