TraderTraitor

THREAT ACTOR PROFILE

TraderTraitor

TraderTraitor

TraderTraitor

TraderTraitor is a North Korean Lazarus subgroup focused on large-scale cryptocurrency theft, tracked as Jade Sleet or UNC4899. It targets developers and DevOps staff at crypto and technology firms through fake job interviews and weaponized developer tooling, and it is tied to some of the largest crypto heists on record, including the Bybit theft.

North Korea

Cryptocurrency / Finance

First seen

2022

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

TraderTraitor, Jade Sleet and UNC4899

TraderTraitor is tracked under several names for the same DPRK crypto-theft activity. It is one entry among the North Korean actors in our database, a subgroup of the Lazarus Group.

-

-

-

-

GROUP PROFILE

Developer-targeted heists for the regime

TraderTraitor steals cryptocurrency to fund North Korea, specializing in compromising developers and DevOps engineers whose access can unlock exchange and wallet infrastructure. It is part of the Lazarus financial ecosystem.

Our record places its origin as North Korea and ties it to financial theft. It is linked to the Bybit heist, assessed as the largest cryptocurrency theft on record, and to earlier operations against exchanges and wallet software.

The group's method is patient social engineering: fake recruiters on LinkedIn deliver weaponized coding assignments, GitHub projects and Terraform files that redirect developer tooling to attacker-controlled modules, executing macOS backdoors on the engineer's machine.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

ATTACK LIFECYCLE

Fake job tests into macOS backdoors

The stages below come from TraderTraitor activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

FLATROOF, ROOFDECK and weaponized dev tooling

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Access through social engineering, not exploits

TraderTraitor's intrusions in our records rely on social engineering (fake job interviews) and weaponized developer tooling (Terraform providers, GitHub projects, npm packages) rather than on exploiting specific software vulnerabilities, so this profile does not list a confirmed exploited-CVE set. Detection should focus on malicious dependency resolution and unexpected macOS backdoor behavior on developer machines.

TraderTraitor

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

TraderTraitor

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

TraderTraitor

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

TraderTraitor

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

Terraform job tests and the Bybit heist

Recent reporting tracks the group's developer-targeting and its record heists.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

TraderTraitor

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

TraderTraitor

IOC set, full IP, host and hash history.