
Alex Delamotte

2026
Don't Call Us, We'll Call Your APIs: Anatomy of an Expanding DPRK Multi-Cloud Intrusion
This presentation explores a multi-cloud intrusion campaign attributed to a North Korean threat actor that abused a tech-forward organization’s own CI/CD pipeline and services to mint cryptocurrency tokens: effectively, to print money by making the servers lie.Â
PUKCHONG (aka TraderTraitor, Jade Sleet) is a financially motivated subgroup of the Lazarus cluster tracked as UNC4899, which supplies the regime with cash flow in spite of sanctions at the direction of the DPRK Reconnaissance General Bureau (RGB). The group is linked to multiple cryptocurrency exchange thefts and a supply-chain attack against a SaaS provider. Through March and April 2026, PUKCHONG engaged in a complex intrusion against a cryptocurrency organization that resulted in the attacker being able to quietly mint their own tokens, leading to a massive financial loss for impacted organizations.Â
It all started with a classic Contagious Interview pretext: a job-seeking developer within the victim organization was approached and tricked into opening a weaponized coding project that delivered a novel backdoor on their corporate workstation. The adversary stole the targeted organization’s cloud platform and GitHub credentials, cloned private code repositories, then conducted methodical, patient infiltration into the victim’s multi-cloud environment, including privilege escalation via Terraform and Google Kubernetes Engine (GKE). Instead of hunting for smart contract vulnerabilities, the attackers used the victim’s environment against itself. They poisoned the memory of compromised servers and used a targeted DDoS to dictate which transactions the validation network accepted to forge a multi-million-dollar minting event without triggering on-chain security alarms.Â
This talk expands on the mechanics used to achieve deep access inside a cloud-native organization, including previously unreported details about how PUKCHONG’s custom implants work. We expand on how the interview coding projects silently installed a backdoored dependency and how these techniques changed over time. We will also share hunting strategies used to identify additional victims in different phases of infiltration.
