Google

Nick Simonian

Nick Simonian

2026

Don't Call Us, We'll Call Your APIs: Anatomy of an Expanding DPRK Multi-Cloud Intrusion

This presentation explores a multi-cloud intrusion campaign attributed to a North Korean threat actor that abused a tech-forward organization’s own CI/CD pipeline and services to mint cryptocurrency tokens: effectively, to print money by making the servers lie. 

 PUKCHONG (aka TraderTraitor, Jade Sleet) is a financially motivated subgroup of the Lazarus cluster tracked as UNC4899, which supplies the regime with cash flow in spite of sanctions at the direction of the DPRK Reconnaissance General Bureau (RGB). The group is linked to multiple cryptocurrency exchange thefts and a supply-chain attack against a SaaS provider. Through March and April 2026, PUKCHONG engaged in a complex intrusion against a cryptocurrency organization that resulted in the attacker being able to quietly mint their own tokens, leading to a massive financial loss for impacted organizations. 

 It all started with a classic Contagious Interview pretext: a job-seeking developer within the victim organization was approached and tricked into opening a weaponized coding project that delivered a novel backdoor on their corporate workstation. The adversary stole the targeted organization’s cloud platform and GitHub credentials, cloned private code repositories, then conducted methodical, patient infiltration into the victim’s multi-cloud environment, including privilege escalation via Terraform and Google Kubernetes Engine (GKE). Instead of hunting for smart contract vulnerabilities, the attackers used the victim’s environment against itself. They poisoned the memory of compromised servers and used a targeted DDoS to dictate which transactions the validation network accepted to forge a multi-million-dollar minting event without triggering on-chain security alarms. 

This talk expands on the mechanics used to achieve deep access inside a cloud-native organization, including previously unreported details about how PUKCHONG’s custom implants work. We expand on how the interview coding projects silently installed a backdoored dependency and how these techniques changed over time. We will also share hunting strategies used to identify additional victims in different phases of infiltration.


About Nick Simonian

Nick Simonian is a Principal Security Researcher at Google, focused on threat hunting, detection engineering, and novel attack research. With a military and intelligence community background, he enjoys focusing on nation-state threats that push the limit of cyber defenses. He's written and contributed to blogs such as "Don't @ Me: URL Obfuscation Through Schema Abuse" and "Unearthing APT44: Russia’s Notorious Cyber Sabotage Unit Sandworm." 

When he's not staring at a debugger, he enjoys the finer things in life like metal detecting and lockpicking.