North Korea-linked Velvet Chollima—also tracked as Kimsuky, APT43, and Microsoft’s Ruby Sleet—ran a financially motivated campaign that used a trojanized cryptocurrency trading application named Tralert FX to compromise retail crypto traders. The operation reportedly began in June 2025 and relied on an EV-signed installer associated with "AgilusTech LLC" to make the lure appear legitimate, then deployed a multi-stage malware chain designed to harvest browser credentials and cryptocurrency wallet data from infected Windows systems.
The intrusion chain established persistence through Windows scheduled tasks and ultimately delivered MoonPeak, a customized .NET XenoRAT variant. Operators used GitLab for both command-and-control and data exfiltration, with infected hosts polling roughly every 30 minutes. Reporting tied the campaign to more than 4,100 operator commits and over 90 compromised hosts at disclosure, indicating a sustained, scalable DPRK monetization effort focused on high-volume theft from individual cryptocurrency users rather than the exchange-focused intrusions more commonly associated with Lazarus.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
By the time of public disclosure, researchers reported more than 4,100 operator commits and over 90 compromised hosts, indicating sustained operational scale. The activity was assessed as a DPRK monetization model distinct from Lazarus-style exchange intrusions, instead targeting individual cryptocurrency users at volume.
Over the course of the campaign, the threat actor used an EV-signed installer tied to "AgilusTech LLC," deployed multiple malware stages, established persistence with Windows scheduled tasks, and used GitLab for command-and-control and exfiltration on roughly 30-minute intervals. The final payload was MoonPeak, described as a customized .NET XenoRAT variant.
In June 2025, Velvet Chollima/Kimsuky began a financially motivated operation using a fake cryptocurrency trading application called Tralert FX to target retail crypto traders. The campaign focused on stealing browser credentials and cryptocurrency wallet data for large-scale account takeover.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcegist.github.com
Open sourcehybrid-analysis.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.