Threadlinqs IntelligenceStart free

Threat actorNorth KoreaTracked since 2026-02

TraderTraitor

Also known as:Lazarus GroupJade SleetPukchongUNC4899Slow PiscesAPT38BlueNoroffStardust ChollimaLabyrinth ChollimaHIDDEN COBRAGuardians of PeaceZINC

As of 2026-09-28, TraderTraitor is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning supply chain, apt, vulnerability. Also known as Lazarus Group, Jade Sleet, Pukchong, UNC4899. ATT&CK coverage spans 81 techniques across 15 tactics in 6 of 6 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1059 (Command and Scripting Interpreter), T1105 (Ingress Tool Transfer).

Tracked threats
63 critical · 3 high
First seen
2026-02-27
Last seen
2026-09-26
ATT&CK techniques
81across 6 of 6 threats
Related CVEs
1Referenced by its activity
Attribution
North KoreaNation or origin
Nation: North Korea · 6 tracked threat(s) · Categories: SUPPLY_CHAIN, APT, VULNERABILITY

Activity timeline

TraderTraitor appears in 6 tracked threats between and ; the busiest month was 2026-04 with 2 reports.

ATT&CK techniques observed

81 techniques observed across 6 of 6 tracked threats · Stealth (formerly Defense Evasion) (14), Discovery (8), Execution (8), Resource Development (8), Command and Control (7), Initial Access (7)
  • T1078 Valid Accounts — Initial Accessobserved in 4 of 6 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 3 of 6 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 6 tracked threats
  • T1657 Financial Theft — Impactobserved in 3 of 6 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 6 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 6 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 6 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 6 tracked threats
  • T1059.007 JavaScript — Executionobserved in 2 of 6 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 2 of 6 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 2 of 6 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 6 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 6 tracked threats
  • T1195.001 Compromise Software Dependencies and Development Tools — Initial Accessobserved in 2 of 6 tracked threats
  • T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 2 of 6 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked TraderTraitor activity