TraderTraitor is a North Korean government-backed threat actor focused on financially motivated cryptocurrency theft. It is also tracked as Jade Sleet, UNC4899, Slow Pisces, Pressure Chollima, Pukchong, and Storm-0954. Its targets include cryptocurrency exchanges, blockchain companies, Web3 organizations, and digital-asset platforms, as well as information technology services providers and developers with access to sensitive infrastructure. The FBI attributed the approximately $1.5 billion theft from Bybit on February 21, 2025, to North Korea and identified the activity as TraderTraitor. The actor uses recruitment-themed social engineering, fake job interviews, impersonation of legitimate companies, and malicious coding assignments to compromise developer workstations. Its operations have used attacker-controlled GitHub repositories and malicious Terraform dependency lock files to deliver malware during development workflows. A documented intrusion against an Indian IT services provider compromised a DevOps engineer's MacBook with access to source code and cloud credentials, demonstrating targeting beyond cryptocurrency businesses. TraderTraitor has deployed the Rust-based FLATROOF and ROOFDECK backdoors. These implants provide remote command execution, reconnaissance, file manipulation and transfer, credential and data theft, persistence, and reverse-shell access. Targeted information includes browser data, terminal history, system information, and macOS keychain data. FLATROOF uses Telegram-based command-and-control, while ROOFDECK incorporates decentralized Nostr-based command-and-control discovery. The actor has replaced deployed implants with modified variants during ongoing intrusions. Stolen cryptocurrency proceeds are moved across multiple blockchains using bridges and exchange services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
39 malware families attributed to this actor across reporting.
34 additional families tracked in Mallory.
136 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected, but not confidently attributed, involvement in a developer-focused supply-chain campaign using a trojanized AWS-themed Terraform provider to deliver cross-platform backdoors and data stealers. The campaign targets developer workstations and CI/CD environments, enabling remote control and theft of browser credentials, session data, and cryptocurrency wallet-extension data.
Suspected of conducting a supply-chain attack through a malicious Terraform provider that executes attacker-controlled code during initialization. The campaign deploys FLATROOF backdoors and stealers to harvest sensitive data and maintain access, followed by ROOFDECK. Attribution to TraderTraitor is suggested by the reference title, not independently substantiated in the supplied summary.
Suspected of using a trojanized Terraform provider to deliver cross-platform malware. The supplied post provides no further operational details.
North Korean government-backed actor known for targeting the cryptocurrency industry. The report links TraderTraitor to a campaign targeting cryptocurrency and Web3 developers through a trojanized Terraform provider that delivers cross-platform FLATROOF malware, information-stealing Python scripts, and ROOFDECK backdoors. The campaign enables credential and cryptocurrency-wallet data theft, persistent access, and remote control. Attribution is based on overlapping tactics, targeting, and malware rather than independently verified technical links; high-confidence attribution remains unestablished.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.