TraderTraitor: Deep Dive
2025-07-28 • Wiz •
https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist
TraderTraitor is presented as a North Korean financially motivated activity cluster focused on stealing cryptocurrency and other digital assets from blockchain and cloud-connected organizations. The excerpt ties the cluster to Lazarus Group, APT38, BlueNoroff, Stardust Chollima, Jade Sleet, TA444, UNC4899, and Slow Pisces, while citing government and industry attribution for major thefts including DMM Bitcoin and Bybit. Its targeting includes cryptocurrency exchanges, DeFi platforms, crypto startups, venture funds, developers, and software or cloud service providers that can provide access to downstream crypto customers. The tradecraft includes recruiter lures over LinkedIn, Slack, and Telegram; fake coding challenges and GitHub collaborations; trojanized Electron and JavaScript trading apps; malicious npm dependencies; compromised code-signing; encrypted C2-delivered second stages such as MANUSCRYPT; and cloud supply-chain abuse such as the JumpCloud compromise. The activity matters because it blends state-sponsored intrusion methods with rapid monetization, moving from social engineering or supply-chain access toward wallet, transaction, and infrastructure compromise.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | getstockprice.com | 2025-03-11 | 2025-12-10 |