TraderTraitor — APT Profile
TraderTraitor targets blockchain companies through spear-phishing messages. The group sends these messages to employees, particularly those in system administration or software development roles, on various communication platforms, intended to gain access to these start-up and high-tech companies. TraderTraitor may be the work of operators previously responsible for APT38 activity.Also tracked as
UNC4899, Jade Sleet
IntelFusions coverage (2)
- Hackers now poison open source packages instead of breaking into vendors 2026-07-31 · Cyber Incidents
- TraderTraitor (Lazarus/UNC4899): JumpCloud Supply Chain Compromise, Bybit $1.5B Safe{Wallet} AWS Session Token Theft, and DMM Bitcoin $308M RN Stealer Campaign 2026-02-16 · Nation-State
Tools & malware
- FULLHOUSE.DOORED Backdoor
- py.rn_stealer Infostealer
- STRATOFEAR Backdoor
- TIEDYE Backdoor
Vendor research
- FBI Statement on North Korea TraderTraitor Responsibility for Bybit Theft FBI IC3
- North Korea Leverages SaaS Provider in a Targeted Supply Chain Attack Mandiant (Google Cloud)
Countries linked to this actor
- Japan targets
- Brazil targets
- North Korea origin
- United States targets