Full Report
Inside the Lazarus subgroup that’s hijacking cloud platforms, poisoning supply chains, and stealing billions in digital assets.
Analysis Summary
# Threat Actor: TraderTraitor
## Attribution & Identity
TraderTraitor is a cluster of North Korean state-sponsored cyber activity, primarily focused on financial gain through cryptocurrency theft. It is tracked as an operation under the broader **Lazarus Group** umbrella, which includes associated entities like APT38, BlueNoroff, and Stardust Chollima. The sponsoring agency is believed to be North Korea’s Reconnaissance General Bureau (RGB), specifically possibly the 3rd bureau (Bureau of Foreign Intelligence).
**Known Aliases:** UNC4899 (GTIG), Jade Sleet (MSTIC), Slow Pisces (Unit42).
## Activity Summary
TraderTraitor has been active since at least 2020, with public mentions emerging in 2022. Its campaigns focus on stealing digital assets (Bitcoin, Ether) to generate revenue for the North Korean state. Major historical activities mentioned include the **JumpCloud supply chain attack** and the **ByBit hack** (late 2024, $1.5 billion stolen). The FBI also attributed a $308 million Bitcoin DMM exchange heist (May 2024) to TraderTraitor actors. Campaigns have evolved from Trojanized Cryptocurrency Applications (2020-2022) to include complex supply chain compromises and diverting legitimate transactions.
## Tactics, Techniques & Procedures
- Leveraging traditional phishing emails.
- Infection with trojanized software.
- Conducting complex operations including supply chain compromises.
- Diverting legitimate transactions.
- Social engineering of multiple employees to gain initial access.
- Use of trojanized open-source packages (npm, PyPI).
## Targeting
- **Sectors:** Blockchain organizations, cryptocurrency exchanges, DeFi platforms, crypto startups, venture funds, and wealthy individual crypto holders. Cloud services and software development platforms have been specifically targeted in supply chain operations.
- **Geography:** Global (implied by targeting of global cloud customers and exchanges).
- **Victims:** Bitcoin DMM exchange, ByBit crypto exchange, JumpCloud.
## Tools & Infrastructure
*Tools/Malware families were not explicitly named beyond the description of trojanized code/software, but the focus is on exploiting software supply chains.*
- **Infrastructure:** Not detailed beyond the attack vectors utilized.
## Implications
TraderTraitor represents a significant, state-sponsored threat focused on illicit financial gain, effectively converting cybercrime into a state revenue stream. Their operational focus on the cryptocurrency sector, coupled with sophisticated supply chain attacks, poses a continuous, high-risk threat not only to digital asset holders but also to the integrity of development environments globally. Intrusions often move rapidly from access to illicit transactions, emphasizing urgency in detection.
## Mitigations
- Focus on securing the software supply chain, especially when incorporating open-source packages (npm, PyPI).
- Implement robust security around crypto transactions and blockchain platforms.
- Vigilance against social engineering targeting employees for initial access.