Anatomy of $10M Heist: UNC4899 Cloud and Kubernetes Evasion
Tuesday, September 15, 2026, 11:00 AM - 11:45 AM
Atrium Ballroom A

This session deconstructs a frontline investigation into a highly targeted campaign by the North Korean threat actor UNC4899, which resulted in a $14 million theft from a cryptocurrency exchange. We trace the complete attack lifecycle, beginning with initial access achieved when the adversary delivered a trojanized Django log monitoring application via AirDrop. By exploiting a Python pickle deserialization flaw, the attackers compromised a developer's macOS endpoint and subsequently hijacked active VPN sessions to silently maneuver into the organization's Google Cloud Platform (GCP) environment. Rather than relying on zero-day exploits, UNC4899 abused existing developer permissions to maliciously patch Google Kubernetes Engine (GKE) deployment configurations, successfully escaping containers to establish persistence on node servers. Finally, the adversary exploited a centralized Cloud SQL Auth Proxy misconfiguration to extract persistent database credentials, alter high-value user accounts, and siphon digital assets across multiple blockchains. Attendees will leave with actionable remediation and architecture hardening strategies to secure Kubernetes secrets, enforce least-privilege controls, and protect cloud workloads against sophisticated adversaries.