TraderTraitor — APT Profile
TraderTraitor targets blockchain companies through spear-phishing messages. The group sends these messages to employees, particularly those in system administration or software development roles, on various communication platforms, intended to gain access to these start-up and high-tech companies. TraderTraitor may be the work of operators previously responsible for APT38 activity.Also tracked as
UNC4899, Jade Sleet, Pukchong
IntelFusions coverage (3)
- North Korea's hacking machine is bigger than Lazarus 2026-09-07 · Nation-State
- Hackers now poison open source packages instead of breaking into vendors 2026-07-31 · Cyber Incidents
- TraderTraitor (Lazarus/UNC4899): JumpCloud Supply Chain Compromise, Bybit $1.5B Safe{Wallet} AWS Session Token Theft, and DMM Bitcoin $308M RN Stealer Campaign 2026-02-16 · Nation-State
Tools & malware
- AlticGO Trojanized cryptocurrency application
- CreAI Deck Trojanized cryptocurrency application
- CryptAIS Trojanized cryptocurrency application
- DAFOM Trojanized cryptocurrency application
- Esilet Trojanized cryptocurrency application
- FULLHOUSE.DOORED Backdoor
- Manuscrypt RAT
- py.rn_stealer Infostealer
- STRATOFEAR Backdoor
- TIEDYE Backdoor
- TokenAIS Trojanized cryptocurrency application
Vendor research
- AA22-108A: TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies CISA / FBI / U.S. Treasury
- FBI Statement on North Korea TraderTraitor Responsibility for Bybit Theft FBI IC3
- North Korea Leverages SaaS Provider in a Targeted Supply Chain Attack Mandiant (Google Cloud)
Countries linked to this actor
- Japan targets
- North Korea origin
- United States targets
- Brazil targets