TraderTraitor is a North Korea-linked threat actor focused primarily on stealing cryptocurrency and generating revenue for the DPRK regime. It is widely tracked under the aliases UNC4899, Jade Sleet, Slow Pisces, and PUKCHONG, and is frequently described as part of, or a subgroup associated with, the broader Lazarus Group ecosystem. TraderTraitor specializes in highly targeted intrusions against cryptocurrency exchanges, decentralized finance platforms, wallet providers, bridge infrastructure, and organizations that support virtual asset operations. The group has repeatedly targeted developers, administrators, and other trusted personnel through social engineering, including fake recruiter approaches and malicious coding challenges delivered through developer platforms and messaging services. In multiple reported operations, the actor compromised developer workstations and then pivoted into cloud or production environments to tamper with frontend code, transaction workflows, or bridge-verification infrastructure. Observed tradecraft includes initial access via phishing and recruiter lures, compromise of developer environments, credential and session theft, reconnaissance inside cloud environments, post-exploitation in macOS and developer-centric ecosystems, selective payload delivery, and manipulation of cryptocurrency transaction logic. Public reporting also links the actor to malicious open-source and package ecosystem abuse, including trojanized repositories and developer-targeted malware that can exfiltrate environment variables and enable arbitrary remote code execution. The group has demonstrated strong operational security, patience, victim validation, and tailored deployment designed to affect only intended targets while minimizing broader exposure. TraderTraitor has been publicly attributed to several major cryptocurrency thefts, including the February 2025 Bybit theft and the April 2026 KelpDAO or LayerZero-related exploit. In the Bybit case, reporting tied the operation to compromise of a trusted Safe{Wallet} relationship and malicious alteration of transaction details through frontend manipulation. In the KelpDAO incident, attribution linked the actor to compromise of infrastructure supporting cross-chain verification, combined with denial-of-service pressure and forged state inputs that enabled fraudulent asset release. Reporting also associates the actor with aggressive laundering of stolen virtual assets across multiple chains and privacy-enhancing services shortly after theft. The actor’s dominant motivation is financial, but the proceeds are consistently described as supporting North Korean state interests, making TraderTraitor a state-sponsored revenue-generation threat actor rather than a conventional profit-seeking cybercriminal group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
89 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison point for laundering behavior in crypto theft cases; not attributed to the Coldcard theft.
Referenced in connection with the AFX security incident via the hashtag #UNC4899, suggesting the post associates this named activity cluster with the incident.
North Korea-aligned activity targeting cryptocurrency and decentralized finance organizations and developers using fake recruiter personas and malicious npm/PyPI packages.
Attributed as the DPRK-linked actor behind the April Kelp DAO/LayerZero bridge exploit and tied to a parallel major crypto heist; the group laundered stolen funds through THORChain, Wasabi, Tornado Cash, and Umbra.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.