U.S. agencies and security researchers linked North Korea’s Lazarus Group—also tracked as APT38, BlueNoroff, Stardust Chollima, and HIDDEN COBRA—to a long-running campaign targeting cryptocurrency exchanges, DeFi platforms, trading firms, venture capital funds, gaming companies, and high-value holders. The operation used spearphishing, fake job offers, fraudulent trading firms, social networking, and even fake Telegram groups to lure victims into downloading trojanized cryptocurrency trading and wallet applications on Windows and macOS, with activity reported across more than 30 countries. Researchers described later activity as an evolution of the earlier AppleJeus campaign, while U.S. agencies said the broader effort continued under the TraderTraitor cluster.
The malicious apps—including Celas Trade Pro, JMT Trading, Union Crypto, Kupay Wallet, CoinGoTrade, Dorusio, Ants2Whale, DAFOM, TokenAIS, CryptAIS, AlticGO, Esilet, and CreAI Deck—appeared legitimate but installed hidden updater components, persistence mechanisms, and remote-access payloads such as Manuscrypt variants. Analysis of Union Crypto showed the malware collecting host details, installing services or LaunchDaemons, contacting command-and-control infrastructure, downloading second-stage payloads, and enabling file operations, screenshots, command execution, lateral movement, theft of private keys, and fraudulent blockchain transactions. U.S. authorities said the campaign supports North Korea’s sanctions evasion and revenue generation, and warned that cryptocurrency and blockchain firms remain likely targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The FBI, CISA, and the U.S. Treasury issued a joint advisory on TraderTraitor, attributing the campaign to North Korean state-sponsored actors tracked as Lazarus Group, APT38, BlueNoroff, and Stardust Chollima. The advisory detailed fake job-offer lures, trojanized apps such as DAFOM and TokenAIS, associated indicators of compromise, and recommended mitigations.
The FBI, CISA, and the U.S. Treasury issued a joint advisory attributing the AppleJeus malware campaign to North Korea's Lazarus Group/HIDDEN COBRA and warning that trojanized cryptocurrency applications had targeted victims in more than 30 countries.
The FBI, CISA, and the U.S. Treasury released malware analysis reports covering multiple AppleJeus variants, including Celas Trade Pro, JMT Trading, Union Crypto, Dorusio, and Ants2Whale, documenting technical behaviors and infrastructure used to steal cryptocurrency.
ESET disclosed that Lazarus-linked AppleJeus activity included a rebranded macOS cryptocurrency trading application bundled with malware. The report added technical detail on how trojanized trading software was being adapted and repackaged to target cryptocurrency users on macOS.
Kaspersky reported that Lazarus had evolved its cryptocurrency theft activity through 2019 into 'Operation AppleJeus Sequel,' using fake trading firms, fraudulent websites, and Telegram groups to trick victims into downloading malware. Confirmed victims included cryptocurrency businesses in the UK, Poland, Russia, and China.
A version of the AppleJeus malware family using the trojanized Union Crypto trading application was discovered in December 2019, with hidden updater components enabling persistence, host profiling, and second-stage payload delivery on Windows and macOS.
The AppleJeus malware campaign, attributed to North Korea's Lazarus Group, was first uncovered in 2018 using trojanized cryptocurrency trading and wallet applications to steal cryptocurrency from victims.
U.S. agencies later assessed that North Korean state-sponsored actors began targeting cryptocurrency and blockchain organizations with the TraderTraitor campaign by at least 2020, using spearphishing and fake job offers tied to trojanized trading and portfolio applications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceus-cert.gov
Open sourcecisa.gov
Open sourceus-cert.gov
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.