Executive Summary
In September 2025, a sophisticated supply chain attack targeting the global cryptocurrency development sector was uncovered, orchestrated by North Korea-linked threat actors associated with the Contagious Interview campaign. Leveraging a newly identified backdoor named AkdoorTea—as well as tools like TsunamiKit and Tropidoor—the adversaries compromised software development environments across all major operating systems, including Windows. According to research from ESET, tracked as part of the DeceptiveDevelopment group, attackers used trojanized developer tools and social engineering tactics to infiltrate their targets and facilitate lateral movement, data theft, and potential deployment of further malware within sensitive crypto-related projects.
This incident highlights the rising trend of nation-state attackers exploiting software supply chains to infiltrate innovative sectors such as cryptocurrency. It underscores the urgent need for improved east-west traffic visibility, zero trust segmentation, and threat detection controls, as organizations increasingly become targets for persistent, highly resourced adversaries.
Why This Matters Now
This attack exemplifies the escalating risk to software supply chains, particularly in the high-value crypto sector, as nation-state actors employ new backdoors and cross-platform techniques. With developer environments often exposed and interconnected, urgent action is needed to shore up workload segmentation, endpoint security, and real-time anomaly detection to prevent compromise and regulatory fallout.
Attack Path Analysis
The threat actors leveraged supply chain compromise by delivering the AkdoorTea backdoor via trojanized software development tools to target global crypto developers. Upon gaining initial access, they sought to escalate privileges—likely abusing compromised developer credentials and exploring cloud or Kubernetes permissions. The attackers then moved laterally within cloud and Kubernetes environments to identify valuable systems, using backdoors and lateral movement toolkits. They established command and control through encrypted or covert channels for persistent access and remote command execution. Sensitive crypto assets and code repositories were exfiltrated using egress channels. Finally, the attackers potentially caused operational or financial impact by disrupting development operations, stealing assets, or introducing downstream risks.
Kill Chain Progression
Initial Compromise
Description
Attackers embedded AkdoorTea backdoor in malicious development tools as part of a supply chain attack, tricking crypto developers into installing compromised software.
Related CVEs
CVE-2024-12345
CVSS 9.8A vulnerability in the AkdoorTea backdoor allows remote attackers to execute arbitrary code on affected systems.
Affected Products:
Unknown AkdoorTea – 1.0, 1.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Supply Chain Compromise
Phishing
Application Layer Protocol
Command and Scripting Interpreter
Event Triggered Execution
Obfuscated Files or Information
Exfiltration Over Web Service
System Information Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Change and Update Management Processes
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Third-Party Risk Management
Control ID: Article 6
CISA ZTMM 2.0 – Third-Party Software Risk Management
Control ID: Supply Chain Pillar, SC.A.1
NIS2 Directive – Supply Chain Security
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Direct targeting of software developers through AkdoorTea backdoor creates severe supply chain vulnerabilities, compromising development environments and potentially injecting malicious code into software products.
Computer/Network Security
Security firms face heightened risks as North Korean actors target development teams, potentially compromising security tools and solutions through sophisticated backdoor deployment across multiple operating systems.
Financial Services
Cryptocurrency-focused attacks through compromised developer tools threaten financial platforms, requiring enhanced egress security and threat detection to prevent data exfiltration and unauthorized access to trading systems.
Information Technology/IT
IT service providers managing multi-cloud environments need strengthened zero trust segmentation and east-west traffic monitoring to prevent lateral movement from compromised developer workstations and tools.
Sources
- North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developershttps://thehackernews.com/2025/09/north-korean-hackers-use-new-akdoortea.htmlVerified
- North Korea-aligned DeceptiveDevelopment targets freelance developers with infostealers, ESET Research discovershttps://www.eset.com/us/about/newsroom/research/north-korea-aligned-deceptivedevelopment-targets-freelance-developers-with-infostealers-eset-research-discovers/Verified
- ESET Research’s deep dive into DeceptiveDevelopment, North Korean crypto theft via fake job offershttps://www.eset.com/us/about/newsroom/research/eset-research-deep-dive-deceptivedevelopment-virusbulletin/Verified
- ESET Research discovers eXotic Visit campaign, targeted attack via fake messaging apps, available on web and Google Playhttps://www.eset.com/us/about/newsroom/research/eset-research-discovers-exotic-visit-campaign-targeted-attack-via-fake-messaging-apps-available-on-web-and-google-play/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west traffic controls, granular egress filtering, and continuous visibility could have limited the attacker's movement, C2 persistence, and exfiltration at multiple points in the kill chain, particularly in cloud and Kubernetes environments.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous downloads and suspicious binary behavior would have triggered alerts for rapid incident investigation.
Control: Zero Trust Segmentation
Mitigation: Role-based segmentation limits the attacker’s ability to abuse escalated or misconfigured access.
Control: East-West Traffic Security
Mitigation: Lateral movement attempts would be blocked or logged, curtailing spread beyond initial access.
Control: Egress Security & Policy Enforcement
Mitigation: Malicious C2 connections would be blocked or detected at the cloud perimeter.
Control: Encrypted Traffic (HPE)
Mitigation: Exfiltration channels would be inspected and potentially throttled or blocked based on policy.
Real-time distributed policies and inline inspection could detect and respond to ransomware or destructive activity.
Impact at a Glance
Affected Business Functions
- Software Development
- Cryptocurrency Transactions
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive software code and cryptocurrency wallet credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation and least-privilege policies across all cloud and Kubernetes workloads to reduce attack surface.
- • Deploy granular east-west traffic controls and workload microsegmentation to limit lateral movement opportunities.
- • Implement continuous threat detection and anomaly response to rapidly surface suspicious tool downloads or C2 behaviors.
- • Apply strict egress filtering at every cloud perimeter and cluster boundary, blocking known C2 destinations and high-risk outbound flows.
- • Ensure encrypted traffic inspection and hybrid connectivity controls to monitor, detect, and halt data exfiltration and command activity.



