# Slow Pisces

> As of 2026-05-30, Slow Pisces is a North Korea / China-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability, apt. Also known as Adept Libra, Altered Spider, Lazarus, TraderTraitor. ATT&CK coverage spans 32 techniques across 14 tactics in 2 of 2 tracked threats. Most-observed techniques: T1059 (Command and Scripting Interpreter), T1078 (Valid Accounts), T1528 (Steal Application Access Token).

- **Nation:** North Korea / China
- **Tracked threats:** 2
- **Categories:** VULNERABILITY, APT
- **Also known as:** Adept Libra, Altered Spider, Lazarus, TraderTraitor, Jade Sleet, HIDDEN COBRA, Diamond Sleet, NICKEL ACADEMY, Labyrinth Chollima, PCPcat, ShellForce, DeadCatx3
- **As of:** 2026-05-30

## ATT&CK techniques observed

32 techniques observed across 2 of 2 tracked threats. Tactics: Discovery (4), Execution (4), Command and Control (3), Impact (3), Initial Access (3), Persistence (3).

- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 2 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 2 tracked threats
- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 2 of 2 tracked threats
- [T1530](https://intel.threadlinqs.com/technique/T1530) Data from Cloud Storage — Collection — observed in 2 of 2 tracked threats
- [T1550](https://intel.threadlinqs.com/technique/T1550) Use Alternate Authentication Material — Lateral Movement — observed in 2 of 2 tracked threats
- [T1552](https://intel.threadlinqs.com/technique/T1552) Unsecured Credentials — Credential Access — observed in 2 of 2 tracked threats
- [T1573](https://intel.threadlinqs.com/technique/T1573) Encrypted Channel — Command and Control — observed in 2 of 2 tracked threats
- [T1611](https://intel.threadlinqs.com/technique/T1611) Escape to Host — Privilege Escalation — observed in 2 of 2 tracked threats
- [T1613](https://intel.threadlinqs.com/technique/T1613) Container and Resource Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 1 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 1 of 2 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Persistence — observed in 1 of 2 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 1 of 2 tracked threats

## Tracked threats

- [Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat Actors](https://intel.threadlinqs.com/threat/TL-2026-0327) — CRITICAL
- [UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure Compromise](https://intel.threadlinqs.com/threat/TL-2026-0202) — CRITICAL

## Related CVEs

1 CVE referenced by tracked Slow Pisces activity.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Slow%20Pisces
