Sapphire Sleet / UNC1069
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2egUDH…o8BRSummary
Sapphire Sleet (Microsoft designation) / UNC1069 (Google Mandiant designation) is a North Korean state-sponsored advanced persistent threat group assessed to operate under the Reconnaissance General Bureau, active since at least 2018. The group is financially motivated and primarily targets cryptocurrency exchanges, DeFi platforms, venture capital funds, wallet providers, and software developers. On March 31, 2026, the group executed a supply chain compromise of the axios npm package — which receives over 100 million weekly downloads — deploying the WAVESHAPER.V2 cross-platform remote access trojan to approximately 600,000 installations during a three-hour exposure window.
Connected Entities
6 entities · 60 linked investigations- Citrine Sleet / AppleJeus→mentioned with→Drift Protocol(80%)
- Axios npm Supply Chain Attack (March 2026)→mentioned with→Sapphire Sleet / UNC1069(80%)
- Drift Protocol→mentioned with→Citrine Sleet / AppleJeus(80%)
- Sapphire Sleet / UNC1069→mentioned with→Axios npm Supply Chain Attack (March 2026)(80%)
- Sapphire Sleet / UNC1069→mentioned with→Citrine Sleet / AppleJeus(80%)
- Sapphire Sleet / UNC1069→mentioned with→Drift Protocol(80%)
- Solana→mentioned with→Drift Protocol(80%)
- Drift→mentioned with→Solana(80%)
- Citrine Sleet / AppleJeus→mentioned with→Solana(60%)
- Citrine Sleet / AppleJeus→mentioned with→Drift(85%)
- + 3 more
Connected Through
6 shared actors · 402 investigationsDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- □Solanaorganizationalso inKelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus·0Q2 2026 Bridge Exploit Wave·0CATFI Memecoin·0BonkDAO Treasury Governance Attack·0Q2 2026 Record Crypto Hack Wave·0Ben Pasternak / Believe / LAUNCHCOIN·0MEV Bot Scam — YouTube AI Trading Bot Campaign (2026)·0Mach-O Man Malware Campaign (Lazarus / Chollima)·0DPRK IT Worker Network (Overseas Scheme)·0Yelo (yelotree)·0Lab·0Solana Blinks / Durable-Nonce Drainer Kits (2026)·0H1 2026 Bridge Hack Cluster — Same-Day $35.6M Attack Wave July 22-23·0Google Coin / Fake Gemini AI Chatbot Presale Operation·0Solana Token-2022 Permanent Delegate Rug Pull Factory·0AI Agent Prompt Injection Crypto Attack Class (2026)·0fake Ledger Live app·0Sam Bankman-Fried·0LAB / LABUSDT·0H2 2026 July Bridge Hack Wave — Seven Attacks, $M+ Lost·0BonkDAO Treasury Governance Attack (July 2026)·0DeFi Governance Attack Wave 2026·0Drift Protocol DPRK Exploit (April 2026)·0Hayden Davis·0HAWK·0Fake Crypto AML Checker Infrastructure·0World Cup 2026 — Stake.com Impersonation Wallet Drainer Campaign·0CATFI Memecoin / Eth Father (Park)·0Fake Jupiter CJUP Airdrop Phishing Campaign·0LAB Token (LabsAI)·0Fake Uniswap V4 Airdrop Phishing Network (2026)·0Adam22 (Adam John Grandmaison) — $CUCK Meme Coin·0Q2 2026 DeFi Record Hack Wave·0Iranian Crypto Exchanges OFAC Designation — Nobitex, Wallex, Bitpin, Ramzinex (June 2026)·0DPRK Lazarus April 2026 $635M Blitz — Drift + Kelp Combined Campaign·0Iggy Azalea / MOTHER Memecoin·0Citrine Sleet / AppleJeus·0Solana MEV Sandwich Bots·0Broox Bauer / Axiom Insider Trading Ring·0requests-secure-v2·0Mass Address Poisoning Campaign (Ethereum 2025-2026)·0npm debug / chalk Supply Chain Attack (September 2025)·0Ill Bloom Vulnerability·0AscendEX (BitMax)·0AI Hallucinations·0Rugproof (Solana Launchpad)·0ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)·0CrediX Protocol Exit Scam·0North Korea Lazarus Group — H1 2026 Systematic Crypto Theft Campaign·0GSD Cloud / Lex Christopherson·0Sector Drainer — DaaS Wallet Drainer with Phantom 0-Day Bypass·0Rust Crypto Clipper Malware — Fake GitHub Stars Campaign·0Pump.fun·0CarbonVote Token·0DSJEX / BG Wealth Sharing Ponzi·0Shai-Hulud / TeamPCP Supply Chain Attack·0H1 2026 Crypto Hack Landscape — AI Agent Attack Vector Emerges·0Quark Drainer·0Holoworld AI — AVA Token Insider Bundling Scheme·0Rug Republic — Coordinated Pump.fun / Solana Bundle-Rug Cluster·0John Daghita (aka Lick) — US Marshals Crypto Theft·0TeamPCP / Mini Shai-Hulud npm Supply Chain Worm·0DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report)·0Apple App Store — Systematic Fake Crypto Wallet Cluster (26 Apps, April 2026)·0Alex Larson Schultz / OverHere Limited (HAWK Memecoin)·0CYBERLEEK Token·0Genesis Global Capital·0HECO Bridge & HTX Exchange Hack·1FaZe Banks (Ricky Bengtson) / MLG Coin·1Socket Security Malicious Browser Extension Campaign August 2026·2Google Coin / Fake Gemini AI Chatbot Presale Scam·2Basis Markets·2HQI Exchange·2Robinhood Chain Scam Ecosystem·2Aqua·2Bitforex·2Wiz Khalifa Pump Fun·2Iran War Panic Crypto Scam Network (ORAMAMA / X Account Manipulation)·2Squid Games (SQUID Token)·2OpenClaw GitHub Phishing Campaign·2CatFi Memecoin (CATFI)·2Baller Ape Club·2Trump Digital Gold (GOLD)·2Transit Finance·2CLAWD Token (Fake ClawdBot AI Scam)·2Leva Heal Limited (Fake Ledger Live App - Apple App Store)·2Luna Yield·2MangoFarmSOL·2Magnate Finance·2LIBRA Token·2RiskOnBlast·2Eric Trump Fake Token·2Avraham Eisenberg·2Glori Finance·2NFTMachine·2ORAMAMA X War-Panic Scam Network·2Kokomo Finance·2Aquabot (AQUA)·2Rublevka Team·2Fake GTA 6 Leak Wallet-Drainer Campaign·2Dragoma·3AudiA6 Mixing Service·3Sahil Arora·3ZKasino·3FQ1tyso61AH1tzodyJfSwmzsD3GToybbRNoZxUBz21p8·3Kylie Jenner X account hack / $KYLIE Solana memecoin scam·3SIGMA Bot·4LAB Token (Smartliquid AI)·4Crypto Beast (ALT Token Influencer)·4YZY Money·4LAB Token·4CrediX Finance·4LAB Token (AI Terminal / Vova Sadkov)·4DogWifTools·4$TRUMP Memecoin — August 2026 SEC Investigation Request·4Kelsier Labs·4Beaverd (@beaverd)·4Pump.fun / Solana Memecoin Launchpad Ecosystem Fraud·4Crypto Beast·4Kelsier Ventures·4Undisclosed KOL Promo Network (ZachXBT Exposé, September 2025)·5JELLY·5Input Output Group (IOG) YouTube Channel Hijack – Deepfake Hoskinson Giveaway Scam·5Cashio·5Nobitex·5Nirvana V1·5Allbridge Core Second Flash-Loan Exploit (July 2026)·6Axiom DEX Insider Trading (Broox Bauer)·8OverHere Limited / Clinton So·8Allbridge Core — Second Flash Loan Exploit via Same Unpatched Vector·8James Wynn·8$TRUMP Memecoin — Presidential Conflict of Interest and Retail Losses·8pump.fun·8Trove Markets·8Allbridge Core — CCTP Base Chain Exploit (August 2026)·8Rhea Finance Exploit (April 2026)·9Nobitex June 2025 Hack (Predatory Sparrow)·10Step Finance Treasury Theft (January 2026)·10DEXX·10Phemex·10Odin.fun·10Bidao·12Meteora / Benjamin Chow·12DeepSnitch AI·12ZachXBT Crypto Influencer Paid-Promotion Leak (200+ Influencers, September 2025)·12Solareum·12MELANIA Memecoin·12Eric Adams / NYC Token·12Waygu / Wagyu·12Undisclosed KOL Paid-Promotion Network (2025)·12Mango Markets·12Step Finance Hack and Shutdown·12ElementalDeFi·12Baton Corporation Ltd (Pump.fun)·12Cypher Protocol·12Allbridge Core Solana Flash Loan Exploit (July 2026)·14Garden Finance·14Arthur Hayes — Maelstrom CIO Exit Liquidity Allegations·14OpenZeppelin AI Exploit Threat Vector·15Remora Markets·16Pump.fun / Solana Labs RICO Class Action·17Pond0x·18FOMO Token·18Cascade Protocol·18Tectonic Protocol·18OlympusDAO·18Noones·18Transit Swap·18WAYGU CASH·18Axiom DEX·18Broox Bauer·18Meteora / M3M3 Token·18Stabble·18Meteora DEX·18Wasabi Protocol·18Believe·18TRUMP Official Memecoin ($TRUMP)·18Baton Corporation (Pump.fun)·18LetsBonk.fun·20Rhea Lend·20Pump.fun / Solana Labs / Jito Labs — RICO MEV Class Action (SDNY 2026)·20Triple-A Treasury Hack (July 2026)·22Hunter Biden ($LAPTOP token)·22Eclipse·22Ratio Finance·22CyberLeek Solana Token·22CyberLeek / CYBERLEEK Solana Token·22Trezor Email Provider Breach (Brevo, September 2026)·22Axiom DEX Employee Insider Trading·22ChainSwap·22Fartcoin·22Ranger Finance·22Smoking·22Odin.Fun·22Predatory Sparrow (Gonjeshke Darande)·22Roman Storm·22Aster (ASTER)·23Metawin·23Goatseus Maximus (GOAT)·23Carrot Protocol·24y00ts·24BigONE Exchange·24Aurory·26Frank DeGods·26BullX·27Shibarium·28Boop (boop.fun)·28DeFiTuna·28ElizaOS / AI16Z (Eliza Labs)·28Aquifer AMM·28Moola Market·28GemPad·28Allbridge·28Texture Finance·28Meteora·28Nirvana Finance·28ACT·28Axiom Trading·28Omm·28Trust Wallet Chrome Extension Hack (December 2025)·28StablR — Multisig Exploit and EURR/USDR Depeg·28Crema Finance·28Bridgers Cross-Chain Swap·28Slope Wallet·28Dunamu / Upbit·30Axiom Exchange — Employee Insider Trading Scandal·30BonkDAO·30Across Protocol Solana Bridge Exploit (July 2026)·30Shiba Inu (SHIB)·31Cropper Finance·32Daos.fun·32Adrena Protocol·32PiggyBank Protocol·32Axiom·32Zinc·32Eleven Finance·32TeleSwap·32Brevo (email marketing platform used by Trezor, BitBox, CoinTracking, Solana Mobile)·32GoonFi·32Axiom (Solana DEX)·32Saga·32Rhea Finance·32Aldrin·32Banana Gun·32Stonk·32Bonk·33Epicentral Labs·34Honeyland·34Andy Ayrey·34DeGods·34Kiln·355CLYzCRa2E8p3NHNrRSs2w5NkHzj5WGmqCF8zYd3PRD7·35Cod3x·36Genopets·37Griffain·37CoinDCX·38Chads NFT·38Ansem / $ANSEM ("Black Bull") creator-coin controversy·38Fogo·38Avici·38Dogwifhat (WIF)·38IoTeX·38Symbiosis Finance·38Thunder Terminal·38MustStopMurad·38BitoPro·38M2 Exchange·38Polycule·38Triple-A·38Save·38Rain·38Bonad·38Grass·38Loopscale·38M2·39Jump Trading·42Chainflip·42Midnight Network / NIGHT Token·42Brevo·42YO Protocol·42Tria·42Allbridge Core·42GooseFX·42Granary Finance (GRAIN)·42Houdini Swap·42SOL Strategies Inc. (STKE)·42Pudgy Penguins·42Zerion Wallet·43GMGN.ai·43Lifinity·47SwissBorg·47Maestro·47Access Protocol·47Flash Trade·48SKR·48BonkBot·49Aptos·50ZRX (0x Protocol)·50Ottersex·507uh2UVF8hpQjLdUwr7gffJWJfymVcjVLVvC7j9tdCuvD·50Fragmetric·50Ledger Live·50Sky (MakerDAO)·51Teraswitch (Solana validator hosting concentration incident)·52Internet Computer·52Decaf·52Leap Wallet·52Drift Protocol·52Avalanche·52USX·52Fomo (fomo.family)·52Claynosaurz·52Hxro Network·53PayPal USD (PYUSD)·53Robinhood Crypto·54Fuse Wallet·54Jupiter Perps·54HEEBOO·54Polygon·54Lulo·55Exponent Finance·55Render Network·55YLDS·56Global Dollar (USDG)·56DRiP Haus·56Famous Fox Federation·57Trezor·57Audius·58Titan Exchange·58Cega·58Upbit·58Helium (HNT)·58Rain Financial (Crypto Card Infrastructure)·58Helium Mobile·58Backpack·59Ondo US Dollar Yield (USDY)·60Light Protocol·61Solana·62Raydium Protocol·62cat in a dogs world·62Raydium AMM·62Matcha·62Circle Internet Financial·62Jupiter Exchange·62Wormhole·62Porkbun·62Dual Finance·62Jito Labs·62Circle·62Phantom Wallet·63Invesco Short Duration US Government Securities Fund (USTB)·63Firedancer·63Wormhole Bridge·63Madlads·65USDGO·66Helius·67Clockwork·68Hivemapper·68Edgevana·69Anza·69Dialect·69Crossmint·70USD Coin (USDC)·71Glow Wallet·72Superteam·72Bybit·72Cardano·72Phoenix Trade·72Ondo Finance·72Circle USYC·73BlazeStake·73Kamino Finance·74Asymmetric Research·77Marinade Finance·79Orca·80BlackRock USD Institutional Digital Liquidity Fund (BUIDL)·82Solana Summit Toronto·82Janus Henderson Anemoy Treasury Fund (JTRSY)·82
- ⌂Drift Protocolprotocolalso inDeFi Governance Attack Wave 2026·0DPRK·0Drift Protocol DPRK Exploit (April 2026)·0Citrine Sleet / AppleJeus·0KelpDAO Bridge Exploit (April 2026)·0H1 2026 Bridge Hack Cluster — Same-Day $35.6M Attack Wave July 22-23·0Lazarus Group Mach-O Man macOS Campaign — 2026·0Mach-O Man Malware Campaign (Lazarus / Chollima)·0DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report)·0DPRK Lazarus April 2026 $635M Blitz — Drift + Kelp Combined Campaign·0CarbonVote Token·0H1 2026 Crypto Hack Landscape — AI Agent Attack Vector Emerges·0KelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus·0Lazarus Group Mach-O Man ClickFix macOS Campaign·0Q2 2026 DeFi Record Hack Wave·0North Korea Lazarus Group — H1 2026 Systematic Crypto Theft Campaign·0Solana Blinks / Durable-Nonce Drainer Kits (2026)·0TraderTraitor / UNC4899·0Q2 2026 Bridge Exploit Wave·0Q2 2026 Record Crypto Hack Wave·0H1 2026 Crypto Project Shutdown Wave (100+ Projects)·7Step Finance Treasury Theft (January 2026)·10AFX Trade Bridge Exploit (July 2026)·12LND·12ElementalDeFi·12Step Finance Hack and Shutdown·12OpenZeppelin AI Exploit Threat Vector·15Drift Protocol·18Alephium Bridge·18Stabble·18Wasabi Protocol·18Echo Protocol·20Corepound·22Ranger Finance·22Carrot Protocol·24Adshares Bridge (ADS)·28CrossCurve Bridge·28Across Protocol Solana Bridge Exploit (July 2026)·30PiggyBank Protocol·32Stake DAO·36Kipseli·38StakeDAO — vsdCRV Deployer Key Exploit (May 2026)·38Osmosis (allBTC / Nomic Bridge Double-Spend Exploit, September 2026)·38Volo Vault·38Drift Protocol·52Leap Wallet·52Hxro Network·53Jupiter Perps·54Circle Internet Financial·62Circle·62Wormhole·62Solana·62Superteam·72
- □Driftorganizationalso inMach-O Man Malware Campaign (Lazarus / Chollima)·0TraderTraitor / UNC4899·0Q2 2026 Bridge Exploit Wave·0KelpDAO / LayerZero Bridge Exploit (April 2026) — DPRK Lazarus·0Q2 2026 Record Crypto Hack Wave·0DeFi Governance Attack Wave 2026·0H1 2026 Bridge Hack Cluster — Same-Day $35.6M Attack Wave July 22-23·0Drift Protocol DPRK Exploit (April 2026)·0Solana Blinks / Durable-Nonce Drainer Kits (2026)·0Lazarus Group Mach-O Man macOS Campaign — 2026·0Lazarus Group Mach-O Man ClickFix macOS Campaign·0Citrine Sleet / AppleJeus·0Q2 2026 DeFi Record Hack Wave·0DPRK Lazarus April 2026 $635M Blitz — Drift + Kelp Combined Campaign·0H1 2026 Crypto Hack Landscape — AI Agent Attack Vector Emerges·0CarbonVote Token·0DPRK·0North Korea Lazarus Group — H1 2026 Systematic Crypto Theft Campaign·0DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report)·0H1 2026 Crypto Project Shutdown Wave (100+ Projects)·7Step Finance Treasury Theft (January 2026)·10AFX Trade Bridge Exploit (July 2026)·12ElementalDeFi·12Step Finance Hack and Shutdown·12LND·12OpenZeppelin AI Exploit Threat Vector·15Wasabi Protocol·18Stabble·18Alephium Bridge·18Echo Protocol·20Corepound·22Ranger Finance·22Carrot Protocol·24CrossCurve Bridge·28Adshares Bridge (ADS)·28Across Protocol Solana Bridge Exploit (July 2026)·30PiggyBank Protocol·32Stake DAO·36Volo Vault·38StakeDAO — vsdCRV Deployer Key Exploit (May 2026)·38Kipseli·38Osmosis (allBTC / Nomic Bridge Double-Spend Exploit, September 2026)·38Drift Protocol·52Leap Wallet·52Hxro Network·53Jupiter Perps·54Solana·62Circle Internet Financial·62Wormhole·62Circle·62Superteam·72
- □Citrine Sleet / AppleJeusorganizationalso inCitrine Sleet / AppleJeus·0DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report)·0CarbonVote Token·0Drift Protocol DPRK Exploit (April 2026)·0Mach-O Man Malware Campaign (Lazarus / Chollima)·0Solana Blinks / Durable-Nonce Drainer Kits (2026)·0TraderTraitor / UNC4899·0North Korea Lazarus Group — H1 2026 Systematic Crypto Theft Campaign·0Q2 2026 Record Crypto Hack Wave·0UNK_DeadDrop North Korea Developer Phishing Campaign·0Q2 2026 DeFi Record Hack Wave·0Radiant V2·10ElementalDeFi·12Stabble·18Ranger Finance·22Drift Protocol·52
- □Sapphire Sleet / UNC1069organization
- □Axios npm Supply Chain Attack (March 2026)organization
Timeline(12 events)
April 2018
UNC1069 becomes active (earliest tracked date per Google Mandiant), focusing on cryptocurrency exchanges in the United States and Japan.
Tenable FAQ on UNC1069 axios attackJune 2020
ClearSky publishes CryptoCore report tracking the group's estimated $200 million minimum theft from cryptocurrency exchanges since 2018.
The Hacker News — Google Attributes Axios npm Supply Chain Attack to UNC1069March 2020
Microsoft begins tracking the threat cluster as Sapphire Sleet, identifying it as a North Korean nation-state actor targeting the cryptocurrency sector.
Microsoft Security Blog — Mitigating the Axios npm supply chain compromise22 November 2024
Microsoft presents at CYBERWARCON noting Sapphire Sleet stole over $10 million in cryptocurrency from multiple companies over a six-month window, using fake VC and recruiter social engineering lures.
Microsoft Security Blog — CYBERWARCON threat intelligenceOctober 2025
Concurrent DPRK-linked group (UNC4736 / Citrine Sleet) begins six-month social engineering operation against Drift Protocol Security Council members, posing as a quantitative trading firm at a major crypto conference.
The Hacker News — Drift $285M DPRK nonce attackFebruary 2026
Google Threat Intelligence publishes report documenting UNC1069's deployment of AI-generated deepfakes, fake Zoom and Teams meetings, ClickFix infection vectors, and a seven-family malware arsenal including WAVESHAPER, HYPERCALL, and SILENCELIFT.
The Hacker News — North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations30 March 2026
Attacker publishes clean decoy package plain-crypto-js@4.2.0 to the npm registry at 05:57 UTC. Malicious plain-crypto-js@4.2.1 published at 23:59 UTC.
Tenable FAQ on UNC1069 axios attack31 March 2026
axios@1.14.1 published at 00:21 UTC and axios@0.30.4 at approximately 01:00 UTC with WAVESHAPER.V2 payload. Socket.dev detects the compromise at 00:05 UTC (approximately 6 minutes after plain-crypto-js@4.2.1 publication). Both malicious axios versions removed from npm registry at approximately 03:15 UTC. Approximately 600,000 installations occur during the roughly 3-hour exposure window.
CISA Alert; SANS Emergency Briefing; Tenable FAQApril 2026
Microsoft publishes initial attribution blog post identifying Sapphire Sleet as the threat actor behind the axios compromise. Drift Protocol loses $285 million in a separate DPRK-linked durable nonce attack attributed to UNC4736/Citrine Sleet.
Microsoft Security Blog; The Hacker News2 April 2026
Google Mandiant confirms attribution of axios attack to UNC1069, publishing technical details and infrastructure overlaps linking the operation to prior UNC1069 WAVESHAPER deployments via AstrillVPN node.
SANS Emergency Briefing16 April 2026
Microsoft publishes a follow-on technical post dissecting Sapphire Sleet's macOS intrusion chain, covering credential theft and elevation of privilege techniques.
Microsoft Security Blog — Dissecting Sapphire Sleet's macOS intrusion20 April 2026
CISA publishes formal alert on the axios npm supply chain compromise with technical IOCs, affected version list, safe downgrade targets, and mitigation guidance.
CISA AlertDecision Log
- hash: 3R2MZqYakLhNonkDCWpoekXkn2Stg4dhk3KjmL2MgKjP
This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 17 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 6/19/2026, 11:05:13 PM
last updated: 7/27/2026, 10:56:26 AM
2 viewsavoid.net — verified advice for a post-truth world