TraderTraitor is a North Korean state-sponsored threat cluster focused primarily on stealing cryptocurrency and other digital assets to generate revenue for the DPRK regime. It is widely tracked as UNC4899, Jade Sleet, Slow Pisces, PUKCHONG, and Storm-0954, and is assessed to operate under the broader Lazarus Group umbrella associated with North Korea’s Reconnaissance General Bureau. Public reporting has also linked the cluster with Lazarus-related naming such as APT38, BlueNoroff, and Stardust Chollima in overlapping government usage and attribution contexts. TraderTraitor has targeted cryptocurrency exchanges, decentralized finance platforms, blockchain infrastructure providers, crypto startups, venture funds, and developers working in Web3 environments. The group has repeatedly pursued access through social engineering, especially recruiter-themed outreach on professional and messaging platforms, and has used fake coding challenges, trojanized cryptocurrency applications, malicious open-source packages, and GitHub-hosted lures to compromise developer workstations. Its operations show a sustained emphasis on cloud-connected development environments and trusted third-party relationships as a path to downstream compromise. The actor’s tooling and intrusion patterns include malicious Electron, JavaScript, Node.js, Python, and package-based delivery chains; staged malware retrieval; in-memory execution; credential theft; theft of SSH keys, browser data, wallet material, cloud configuration files, and temporary cloud session credentials; and abuse of stolen session cookies or tokens to access internal systems. Reported malware associated with these operations includes MANUSCRYPT as well as RN Loader and RN Stealer. Observed post-compromise activity includes reconnaissance, remote command execution, exfiltration of sensitive data, tampering with hosted web applications, and selective manipulation of cryptocurrency transaction workflows. TraderTraitor has been tied to software and supply-chain compromise activity in addition to direct endpoint intrusion. Reported operations include malicious npm dependency campaigns against blockchain and fintech developers, the 2023 JumpCloud intrusion affecting a small number of cryptocurrency-industry customers, compromise of developer environments at organizations connected to digital asset services, and frontend tampering in trusted wallet or bridge-related infrastructure. In major incidents, the group has used stolen cloud credentials and session tokens to access SaaS or cloud environments, enumerate assets, and modify web application code so that high-value transactions are redirected to attacker-controlled destinations. The cluster has been publicly attributed to several major cryptocurrency thefts, including the DMM Bitcoin theft, the Bybit theft, and the KelpDAO or LayerZero-related exploit. In these operations, TraderTraitor combined social engineering, developer compromise, cloud access abuse, supply-chain intrusion, and transaction manipulation. The group is also known for rapidly laundering stolen assets across multiple blockchains and privacy-enhancing services shortly after theft, reflecting a mature financial operations capability tightly aligned with regime revenue generation rather than conventional espionage objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
61 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
35 malware families attributed to this actor across reporting.
30 additional families tracked in Mallory.
89 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison point for laundering behavior in crypto theft cases; not attributed to the Coldcard theft.
Referenced in connection with the AFX security incident via the hashtag #UNC4899, suggesting the post associates this named activity cluster with the incident.
North Korea-aligned activity targeting cryptocurrency and decentralized finance organizations and developers using fake recruiter personas and malicious npm/PyPI packages.
Attributed as the DPRK-linked actor behind the April Kelp DAO/LayerZero bridge exploit and tied to a parallel major crypto heist; the group laundered stolen funds through THORChain, Wasabi, Tornado Cash, and Umbra.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.