logo

TraderTraitor: Deep Dive

ID: 4cd0f1c0-840b-543a-b2ca-cdcba4c07e42

STIX ID: report--4cd0f1c0-840b-543a-b2ca-cdcba4c07e42

Feed Name: Wiz Blog

Threat Score
95/100

Date Published: 2025-07-28

Date Updated: 2026-05-01

...
...

TraderTraitor is a financially motivated North Korean subgroup of Lazarus active since at least 2020 that targets cryptocurrency exchanges, developers, and cloud/supply-chain providers using social engineering, trojanized applications, poisoned open-source packages, and cloud credential theft; the report maps their MITRE-based TTPs, catalogs malware (e.g., RN Loader/Stealer, MANUSCRYPT, GopherGrabber), describes major incidents including the DMM/Ginco $308M theft and the Bybit ~$1.5B heist, and recommends cloud-focused detection and prevention controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.