RN Stealer is a Python-based infostealer associated with the North Korean threat cluster commonly tracked as TraderTraitor, Jade Sleet, Slow Pisces, and UNC4899 under the broader Lazarus umbrella. It has been used in financially motivated operations targeting cryptocurrency and blockchain organizations, particularly developers and cloud-connected engineering environments.
RN Stealer is designed to harvest sensitive data from compromised developer workstations. Reported collection targets include saved credentials, SSH keys, cloud service configuration data, and other developer-relevant artifacts. On macOS systems, observed targeting has included keychain data, SSH material, installed application information, home-directory contents, and configuration files associated with major cloud and orchestration platforms such as AWS, Kubernetes, and Google Cloud. The malware generates a victim identifier for command-and-control communications, obtains an encryption key from the server, and encrypts exfiltrated data before transmission.
The malware has been observed as part of a staged infection chain in which RN Loader delivers RN Stealer in memory. In documented campaigns, operators posed as recruiters and sent cryptocurrency developers trojanized coding challenges hosted on GitHub. A Python-based lure used unsafe YAML deserialization to execute the initial payload, after which RN Loader deployed RN Stealer selectively to validated victims. This tradecraft aligns with TraderTraitor’s broader pattern of social engineering, selective payload delivery, strong operational security, and focus on stealing credentials and cloud access from developer environments.
RN Stealer has been linked to intrusions that enabled theft of session material and cloud-connected access, contributing to downstream compromise of internal systems and cryptocurrency-related operations. Its role in these campaigns reflects a broader strategic emphasis on compromising trusted development workflows and cloud-adjacent assets as a path to large-scale financial theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware, identified as RN Loader and RN Stealer, harvested sensitive data including SSH keys, saved credentials, and cloud configurations.
However, we recovered a Python-based infostealer delivered by option 2, and we track this malware as RN Stealer. RN Stealer first generates a random victim ID, subsequently used as a cookie in all communications to the C2 server. It then requests an XOR key from the server for encrypting exfiltrated data.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE Tactic Technique & ID ... Persistence Valid Accounts (T1078) Stolen credentials (cookies, keys) used to maintain access as a legitimate user.
“...posing as potential employers and sending malware disguised as coding challenges... require developers to run a compromised project...” ; “...ran the script without inspecting its contents... hidden malware... credentials... stolen...”
Slow Pisces began by impersonating recruiters on LinkedIn and engaging with potential targets, sending them a benign PDF with a job description... attackers presented them with a coding challenge... which links to a GitHub repository.
The repositories contained code adapted from open-source projects... The malicious command-and-control (C2) server is configured to mimic the format of the legitimate sources... domains... frequently using subdomains like .api or .cdn.
RN Stealer... steal[s]... Configuration files for AWS, Kubernetes and Google Cloud.
The malware, identified as RN Loader and RN Stealer, harvested sensitive data including SSH keys, saved credentials, and cloud configurations [T1552.004].
Communication with the C2 server occurs over HTTPS, using Base64-encoded tokens to identify request and response types... It then requests an XOR key from the server for encrypting exfiltrated data.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named stealer referenced in TraderTraitor-related reporting.
RN Stealer is a Python-based information stealer used by TraderTraitor to harvest SSH keys, saved credentials, and cloud service configurations from compromised developer workstations, facilitating further compromise of cloud assets.
Python-based infostealer used by TraderTraitor to steal SSH keys, saved credentials, cloud configurations, and session material from developer systems.
Stealer malware deployed by North Korean threat actors to exfiltrate sensitive data from infected cryptocurrency developers' systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.