{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:22:43.198Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"DPRK actor posing as a former contractor took $50M from Radiant Capital","date":"2024-10","date_precision":"month","victim_org":"Radiant Capital","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI-generated media was reported; the impersonation relied on a spoofed contractor domain and an existing working relationship.","outcomes":["Cryptocurrency Theft"],"loss_usd":50000000,"loss_note":"Approximately $50 million, with stolen funds moved on October 24, 2024. Radiant Capital later wound down operations.","records_affected":null,"threat_actor":"UNC4736 / Citrine Sleet (DPRK-nexus), assessed with high confidence by Mandiant","summary":"Radiant Capital lost about $50 million in October 2024. On September 11, a threat actor impersonating a trusted former contractor messaged a Radiant developer on Telegram from a spoofed version of the contractor's real domain and shared a ZIP file framed as a request for feedback. The file was passed among other developers, spreading malware. Mandiant attributed the attack with high confidence to a DPRK-nexus actor tracked as UNC4736.","how_it_worked":"The pretext worked because the sender was someone the team already knew and the ask, review this document, was ordinary. The ZIP contained a decoy PDF that opened normally while a macOS backdoor installed behind it, and because the developer forwarded the file to colleagues for their input, the compromise multiplied across the signer group. With malware on multiple developer machines, the attackers manipulated what those machines displayed: front-end interfaces and simulation tools such as Tenderly showed benign transaction data while malicious transactions were being signed underneath. Radiant noted that traditional checks and simulations showed no obvious discrepancies, so the review process that should have caught the theft confirmed it instead.","lessons":"Signing must happen on dedicated, hardened devices that do nothing else, with the transaction independently verified on separate hardware, because once the reviewer's endpoint is compromised, on-screen verification is worthless.","confidence":"Reported","sources":[{"title":"Radiant Capital says North Korea posed as ex-contractor to carry out $50M hack","url":"https://cointelegraph.com/news/radiant-capital-north-korean-impersonated-ex-contractor-50-million-hack","publisher":"Cointelegraph"},{"title":"Radiant Capital Says DPRK Actor Posed as Ex-Contractor to Pull Off $50 Million Hack","url":"https://decrypt.co/295545/radiant-capital-says-dprk-actor-posed-as-ex-contractor-to-pull-off-50-million-hack","publisher":"Decrypt"}],"entry_type":"incident","slug":"2024-dprk-actor-posing-as-a-former-contractor-took-50m-from-radiant-capital","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-dprk-actor-posing-as-a-former-contractor-took-50m-from-radiant-capital"}]}