Lazarus Subgroup 'TraderTraitor' Attacking Cloud Platforms and Poisoning Supply Chains

TraderTraitor, a Lazarus-linked group, uses trojans and supply chain hacks to steal billions in crypto via advanced cloud.

Cyber Security News
"Substantial Upgrades to Crawling History, Artifact Collection" published by Validin. #Bybit, #TraderTraitor, #DPRK, #CTI https://www.validin.com/blog/crawl_history_artifact_upgrade
Substantial Upgrades to Crawling History, Artifact Collection | Validin

Substantial Upgrades to Crawling History, Artifact Collection

Validin
"Bit ByBit - emulation of the DPRK's largest cryptocurrency heist" published by Elastic. #Bybit, #SafeWallet, #TraderTraitor, #DPRK, #CTI https://www.elastic.co/security-labs/bit-bybit
Bit ByBit - emulation of the DPRK's largest cryptocurrency heist — Elastic Security Labs

A high-fidelity emulation of the DPRK's largest cryptocurrency heist via a compromised macOS developer and AWS pivots.

"Analysis of TraderTraitor’s GopherGrabber Malware observed by Willo Campaign" published by S2W. #GopherGrabber, #TraderTraitor, #Willo, #DPRK, #CTI https://s2w.inc/en/resource/detail/806
"TraderTraitor: The Kings of the Crypto Heist" published by Wired. #News, #TraderTraitor, #DPRK, #CTI https://www.wired.com/story/tradertraitor-north-korea-crypto-theft/
TraderTraitor: The Kings of the Crypto Heist

Allegedly responsible for the theft of $1.5 billion in cryptocurrency from a single exchange, North Korea’s TraderTraitor is one of the most sophisticated cybercrime groups in the world.

WIRED

TraderTraitor: The Kings of the #Crypto #Heist

Allegedly responsible for the theft of $1.5 billion in #cryptocurrency from a single exchange, North Korea’s #TraderTraitor is one of the most sophisticated #cybercrime groups in the world.
#northkorea #security

https://www.wired.com/story/tradertraitor-north-korea-crypto-theft/

TraderTraitor: The Kings of the Crypto Heist

Allegedly responsible for the theft of $1.5 billion in cryptocurrency from a single exchange, North Korea’s TraderTraitor is one of the most sophisticated cybercrime groups in the world.

WIRED
Demystifying the North Korean Threat

There’s more to the DPRK than just Lazarus Group.

Paradigm
Safe{Wallet} Confirms North Korean TraderTraitor Hackers Stole $1.5 Billion in Bybit Heist

Bybit’s $1.5B crypto heist linked to North Korean hackers. 77% of funds remain traceable, while Web3 losses hit $1.6B in 2025

The Hacker News

#SafeWallet published the results of an investigation into #NorthKorea's theft of $1.4 billion worth of ethereum from #Bybit.

https://x.com/safe/status/1897663514975649938

#infosec #mandiant #cybersecurity #crypto #DPRK #TraderTraitor #LazarusGroup

Safe.eth (@safe) on X

Investigation Updates and Community Call to Action

X (formerly Twitter)
FBI: North Korea-linked TraderTraitor is responsible for $1.5 Billion Bybit hack

The FBI confirmed that North Korea is responsible for the record-breaking cyber heist at the crypto exchange Bybit.

Security Affairs