TraderTraitor is a North Korea-linked threat cluster/subgroup associated with the Lazarus Group and also referenced alongside APT38. The content describes it as a major threat to the cryptocurrency and blockchain ecosystem, targeting blockchain organizations, cryptocurrency exchanges, and cloud service providers. Reported activity includes social engineering of victims over platforms such as LinkedIn, Telegram, and Discord, often using fake job offers or coding challenges to induce targets to download trojanized cryptocurrency applications on Windows or macOS, as well as supply-chain compromises and abuse of legitimate platforms such as GitHub and npm.
The malware and intrusion activity attributed to TraderTraitor includes trojanized cryptocurrency applications and multi-stage payload delivery. In the macOS-focused activity described by CISA, victims were lured into running trojanized apps such as Esilet.dmg, DAFOM-1.0.0.dmg, TokenAIS.app.zip, CryptAIS.dmg, and darwin64.bin. One analyzed sample, Esilet, was an unsigned Electron-based application that downloaded and executed a second-stage backdoor identified as NukeSped (also called Manuscrypt). That backdoor established persistence via a LaunchAgent plist (com.applex.services.agent.agent.plist), used libcurl for command-and-control communications, and supported reconnaissance, arbitrary shell command execution, and file operations. C2 infrastructure mentioned for this activity includes www.vinoymas.ch, sche-eg.org, and infodigitalnew.com.
Additional malware and tooling associated with TraderTraitor in the content includes RN Loader and RN Stealer, described as Python-based information stealers that harvest SSH keys, saved credentials, and cloud service configurations. The group’s malware is described as being built with JavaScript, Node.js, and Electron, using hardcoded C2 URLs and AES-256 encryption. The content also states that TraderTraitor conducts cloud reconnaissance, including enumeration of IAM roles and S3 buckets, and attempts to register virtual MFA devices for persistence.
The group is linked in the content to major financially motivated cryptocurrency thefts, including the February 2025 Bybit theft of approximately USD 1.5 billion, which the FBI attributed to Lazarus Group/TraderTraitor/APT38. In that incident, the attackers reportedly exploited a transfer from a cold wallet to a hot wallet, rerouted funds to attacker-controlled addresses, and laundered the proceeds across thousands of blockchain addresses. The content also links TraderTraitor to the DMM Bitcoin heist and to a supply-chain compromise involving Safe{Wallet}. It further notes overlap between infrastructure from the July 2023 JumpCloud intrusion and infrastructure patterns associated with TraderTraitor and AppleJeus.
Infrastructure and indicators mentioned in connection with the broader activity include domains such as alwaysckain.com, canolagroove.com, centos-pkg.org, centos-repos.org, datadog-cloud.com, datadog-graph.com, launchruse.com, nomadpkg.com, nomadpkgs.com, primerosauxiliosperu.com, reggedrobin.com, toyourownbeat.com, zscaler-api.org, npmaudit.com, npm-pool.org, npmjscloud.com, npmcloudjs.com, nodepkg.com, dadiwarm.com, npmjsregister.com, tradingprice.net, bi2price.com, junknomad.com, insatageram.com, and celasllc.com. IPs cited in the associated infrastructure include 51.254.24.19, 185.152.67.39, 70.39.103.3, 66.187.75.186, 104.223.86.8, 100.21.104.112, 23.95.182.5, 78.141.223.50, 116.202.251.38, 89.44.9.202, 192.185.5.189, 162.241.248.14, 179.43.151.196, 45.82.250.186, 162.19.3.23, 144.217.92.197, 23.29.115.171, 167.114.188.40, 91.234.199.179, 216.189.145.247, and 142.44.178.222. The content cautions that some infrastructure, such as 192.185.5.189, is shared hosting and should not be treated as a standalone malicious indicator.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Intrusions begin with a large number of spearphishing messages sent to employees of cryptocurrency companies—often working in system administration or software development/IT operations (DevOps)—on a variety of communication platforms. The messages often mimic a recruitment effort and offer high-paying jobs to entice the recipients to download malware-laced cryptocurrency applications.
The response is written to disk and executed in a new shell using the child_process.exec() method in Node.js.
The update function makes an HTTP POST request to a PHP script hosted on the TraderTraitor project’s domain at either the endpoint /update/ or /oath/checkupdate.php.
138 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TraderTraitor is a North Korean cyber espionage malware toolkit used by the Lazarus Group, specializing in targeting cryptocurrency and blockchain organizations. It employs social engineering, trojanized applications, and supply chain attacks to compromise developer workstations and cloud environments, stealing credentials, SSH keys, and cloud configurations.
Malware used in supply-chain compromise of Safe{Wallet}, resulting in large-scale cryptocurrency theft attributed to TraderTraitor APT group.
TraderTraitor is a malware toolkit used by the Lazarus Group for large-scale cryptocurrency theft, enabling the interception and redirection of digital assets, often as part of North Korean state-sponsored cyber operations.
Named DPRK-linked malware/campaign referenced in connection with similar attacker infrastructure associated with the JumpCloud intrusion and related package-themed infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.