FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com

2024-12-23 USFBI

https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom

Thumbnail for FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com

The FBI, DC3, and Japan's National Police Agency attributed the May 2024 theft of 4,502.9 BTC from DMM Bitcoin to North Korean TraderTraitor activity, also tracked as Jade Sleet, UNC4899, and Slow Pisces. The intrusion began when an actor posing as a recruiter on LinkedIn sent a Ginco employee a GitHub-hosted malicious Python script under the cover of a pre-employment test. After compromising the employee, the actors used session cookie data to impersonate the victim inside Ginco's communications system and manipulate a legitimate DMM transaction request, moving the stolen funds to TraderTraitor-controlled wallets.

Related Actors

Related Reports

« Back