Wiz Threat Research published a deep-dive on Wiz on TraderTraitor — a North Korean cryptocurrency theft operation under the Lazarus Group umbrella (also tracked as UNC4899, Jade Sleet, Slow Pisces), first publicly named in a 2022 FBI/CISA/Treasury joint advisory. Sponsored by the RGB (Reconnaissance General Bureau), TraderTraitor has been attributed to the largest known cryptocurrency thefts including the $308M DMM Bitcoin heist and the $1.5B Bybit hack, funding DPRK state programs under international sanctions.
Trojanized Crypto Apps and NPM Supply Chain Poisoning (2020–2023): MANUSCRYPT, RN Loader, RN Stealer
Early campaigns (2020–2022) used LinkedIn/Slack/Telegram fake job recruiter lures to deliver trojanized Electron/Node.js cryptocurrency applications signed with compromised Apple code-signing certificates, containing AES-256-encrypted second-stage payloads delivered from hardcoded C2 URLs — ultimately installing MANUSCRYPT RAT for credential and crypto wallet harvesting. In 2023, operators pivoted to GitHub-based supply chain attacks: impersonating developers, establishing trust via LinkedIn, then inviting targets to collaborate on repositories containing malicious npm packages. GitHub/Jade Sleet attribution led to account suspensions. The July 2023 JumpCloud compromise demonstrated cloud supply chain capability: TraderTraitor spear-phished JumpCloud's platform, then abused JumpCloud's privileged identity management access to push a malicious update to fewer than five cryptocurrency industry customers — bypassing traditional network-based defenses entirely.
DMM Bitcoin Heist ($308M): Ginco Developer Python Script, SSH Key Theft, Session Cookie Replay
In March 2024, a TraderTraitor operative posed as a recruiter and delivered a malicious Python script via a fake GitHub coding challenge to a Ginco developer. The malware (RN Loader/RN Stealer) exfiltrated SSH keys, saved credentials, cloud configuration files, and browser session cookies. Using the stolen session cookies, attackers accessed Ginco's internal systems, breached an unencrypted communication channel linked to DMM Bitcoin, and in late May 2024 diverted 4,502.9 BTC (~$308M) in a fraudulent transaction. The FBI and Japan's NPA formally attributed the heist to TraderTraitor.
Bybit Hack ($1.5B): AWS Session Token Theft, IAM Enumeration, and Safe{Wallet} Next.js Frontend Injection
The Bybit heist (late 2024) demonstrates TraderTraitor's cloud-native attack evolution. In early February 2025, attackers registered C2 domain getstockprice[.]com and compromised a Safe{Wallet} developer's macOS workstation via a malicious Python/Docker application delivered through Telegram or Discord social engineering. Stolen AWS session tokens were used to access Safe{Wallet}'s cloud environment; attackers attempted to register a virtual MFA device for persistence, then enumerated IAM roles, S3 buckets, and cloud assets throughout mid-February. By late February, they injected malicious JavaScript into Safe{Wallet}'s statically hosted Next.js frontend — designed to detect Bybit transactions in real time and redirect funds to attacker-controlled wallets — before scrubbing the script post-execution. The FBI attributed the operation to TraderTraitor in January 2025, confirming Safe{Wallet} as the supply chain entry point rather than Bybit's own infrastructure. Total stolen: over 400,000 ETH and staked ETH (~$1.5B).