Trader Traitor
2022-04-18 • USCISA • TraderTraitor: North Korean State-Sponsored APT T…
The FBI, CISA, and US Treasury introduced the name TraderTraitor in an April 2022 advisory for a North Korean state-sponsored group active since at least 2020, overlapping with activity industry researchers track as Lazarus Group, APT38, BlueNoroff, and Stardust Chollima. Its hallmark technique is spearphishing employees of cryptocurrency exchanges, DeFi platforms, trading firms, and blockchain-gaming companies, often through fake recruiter outreach or bogus pre-employment coding tests, to deliver trojanized cross-platform cryptocurrency applications or malicious code copied into a victim's repository. These payloads can enable theft of private keys and fraudulent blockchain transactions. US authorities later attributed several major thefts to this activity, including the Harmony Horizon Bridge theft, the 2024 DMM Bitcoin exchange theft following a fake GitHub coding test sent to a wallet-software employee, and the February 2025 Bybit exchange theft. A joint FBI, DC3, and Japanese National Police Agency advisory also noted that the activity is tracked as Jade Sleet, UNC4899, and Slow Pisces.
-
34
Related Actors
-
28
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster