TraderTraitor: Deep Dive

2025-07-28 Wiz

https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist

Thumbnail for TraderTraitor: Deep Dive

TraderTraitor is presented as a North Korean financially motivated activity cluster focused on stealing cryptocurrency and other digital assets from blockchain and cloud-connected organizations. The excerpt ties the cluster to Lazarus Group, APT38, BlueNoroff, Stardust Chollima, Jade Sleet, TA444, UNC4899, and Slow Pisces, while citing government and industry attribution for major thefts including DMM Bitcoin and Bybit. Its targeting includes cryptocurrency exchanges, DeFi platforms, crypto startups, venture funds, developers, and software or cloud service providers that can provide access to downstream crypto customers. The tradecraft includes recruiter lures over LinkedIn, Slack, and Telegram; fake coding challenges and GitHub collaborations; trojanized Electron and JavaScript trading apps; malicious npm dependencies; compromised code-signing; encrypted C2-delivered second stages such as MANUSCRYPT; and cloud supply-chain abuse such as the JumpCloud compromise. The activity matters because it blends state-sponsored intrusion methods with rapid monetization, moving from social engineering or supply-chain access toward wallet, transaction, and infrastructure compromise.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN getstockprice.com 2025-03-11 2025-12-10

Related Actors

Related Reports

« Back