FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com
2024-12-23 • USFBI •
The FBI, DC3, and Japan's National Police Agency attributed the May 2024 theft of 4,502.9 BTC from DMM Bitcoin to North Korean TraderTraitor activity, also tracked as Jade Sleet, UNC4899, and Slow Pisces. The intrusion began when an actor posing as a recruiter on LinkedIn sent a Ginco employee a GitHub-hosted malicious Python script under the cover of a pre-employment test. After compromising the employee, the actors used session cookie data to impersonate the victim inside Ginco's communications system and manipulate a legitimate DMM transaction request, moving the stolen funds to TraderTraitor-controlled wallets.
Related Actors
Related Reports
Shares tags: TraderTraitor, DMM • Published within a week
2023-08-22 •
56% Match
#APT38
#News
#Cryptocurrency
#TraderTraitor
#Harmony
#AtomicWallet
#AxieInfinity
#Alphapo
#CoinsPaid
Shares tags: News, TraderTraitor • Same author: USFBI
2023-01-23 •
56% Match
FBI Confirms Lazarus Group, APT38 Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft
USFBI
Shares tags: News, TraderTraitor • Same author: USFBI
Shares tag: TraderTraitor • Same author: USFBI
Shares tag: TraderTraitor • Published within a month
Shares tag: TraderTraitor • Published within a month