North Korea-linked Lazarus Group, including the TraderTraitor cluster, targeted cryptocurrency exchanges, blockchain firms, and developers with social-engineering lures that delivered trojanized Python projects, fake code-evaluation repositories, malicious open-source packages, and compromised applications. Reporting tied the activity to campaigns that tricked victims into running files such as StockInvestSimulator-main.zip and MonteCarloStockInvestSimulator-main.zip, abusing unsafe PyYAML deserialization for remote code execution, while newer intrusion chains used heavily obfuscated Python and a six-stage flow that added TSUNAMI/TSUNAMIKit tooling beyond Lazarus’s previously observed Python-based payloads.
Once inside, the attackers backdoored systems, stole credentials, SSH keys, browser wallet data, cloud credentials, and AWS session tokens, then moved laterally into internal services and wallet infrastructure to transfer digital assets. The activity was also linked to deployment of AnyDesk, keylogging, and XMRig cryptominers, and to broader cloud and SaaS tampering that redirected cryptocurrency transactions; public attributions have connected the cluster to major thefts including the DMM Bitcoin and Bybit heists, underscoring an ongoing campaign against crypto-sector development and production environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
22 events from the most recent confirmed update back to the earliest known activity.
A later LinkedIn post said a previous Lazarus campaign in November 2024 used a compromised Bitbucket repository as the initial lure while keeping largely the same TTPs as the newer campaign.
SlowMist said the attackers scanned internal networks, exploited internal services, stole SSH keys, moved laterally using trusted server relationships, and ultimately transferred cryptocurrency assets from wallet infrastructure they controlled.
According to SlowMist, the attackers persuaded victims to enable privileged mode in docker-compose.yaml, allowing privilege escalation and full control of the target device.
SlowMist said the tampered project added a file named data_fetcher.py that abused yaml.load with attacker-controlled content, enabling remote code execution and backdoor deployment.
SlowMist reported that the campaign used malicious archives such as StockInvestSimulator-main.zip and MonteCarloStockInvestSimulator-main.zip, disguised as legitimate Python projects, to gain initial access to exchange employees’ systems.
SlowMist said it investigated multiple hacking incidents affecting cryptocurrency-related organizations beginning in June 2024 and attributed the campaign to the Lazarus Group.
In late May 2024, attackers diverted 4,502.9 BTC, worth about $308 million, in a fraudulent transaction affecting DMM Bitcoin.
The malware used in the Ginco intrusion was identified as RN Loader and RN Stealer, which harvested SSH keys, saved credentials, and cloud configuration data from the victim system.
In March 2024, a TraderTraitor operative posing as a recruiter tricked a Ginco developer into running a malicious Python script from a fake GitHub coding challenge.
The FBI and Japanese authorities formally attributed the DMM Bitcoin theft to TraderTraitor.
After the Ginco compromise, the attackers used stolen session cookies to access Ginco’s internal systems and an unencrypted communication channel linked to DMM Bitcoin.
In July 2023, TraderTraitor compromised JumpCloud and used the provider’s privileged access to push a malicious update to a small number of cryptocurrency-industry customers. JumpCloud later disclosed that fewer than five customers were impacted.
In late 2023, Elastic Security Labs discovered a novel intrusion targeting blockchain engineers at a prominent cryptocurrency exchange platform. The attackers used Discord social engineering and a fake cryptocurrency arbitrage bot to deliver the previously undisclosed KANDYKORN macOS backdoor through a multi-stage loader chain.
Mandiant attributed the JumpCloud intrusion to TraderTraitor after investigating one victim of the 2023 breach.
GitHub identified the actor behind the malicious npm and repository campaign as North Korea’s Jade Sleet or TraderTraitor and suspended the malicious accounts and repositories.
In early 2023, TraderTraitor expanded into open-source software supply-chain attacks using malicious npm dependencies in GitHub collaboration lures, primarily targeting developers at blockchain and fintech firms.
An April 2022 joint advisory by the FBI, CISA, and the U.S. Treasury linked TraderTraitor to Lazarus Group, APT38, BlueNoroff, and Stardust Chollima.
From 2020 through 2022, TraderTraitor used phishing messages on LinkedIn, Slack, and Telegram, often posing as recruiters to convince employees at crypto companies to download fake cryptocurrency applications.
Wiz reported that the North Korean TraderTraitor cluster had conducted campaigns targeting cryptocurrency organizations since at least 2020, using social engineering, trojanized software, and supply-chain compromise techniques.
Because it assessed the attacks on cryptocurrency exchanges as ongoing and escalating, SlowMist publicly released attacker infrastructure, GitHub accounts, and TTPs to help defenders.
The LinkedIn analysis said the campaign introduced TSUNAMI/TSUNAMIKit components that extended the infection chain beyond Lazarus’s previously known Python-based third stage into a six-stage chain.
A later LinkedIn post described Lazarus launching a new fraudulent campaign after the November 2024 activity, using fake personas and GitLab-hosted code-evaluation lures to target developers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
linkedin.com
Open sourcewiz.io
Open sourceslowmist.medium.com
Open sourcevirusbulletin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.