# TraderTraitor

> As of 2026-09-28, TraderTraitor is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning supply chain, apt, vulnerability. Also known as Lazarus Group, Jade Sleet, Pukchong, UNC4899. ATT&CK coverage spans 81 techniques across 15 tactics in 6 of 6 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1059 (Command and Scripting Interpreter), T1105 (Ingress Tool Transfer).

- **Nation:** North Korea
- **Tracked threats:** 6
- **Categories:** SUPPLY_CHAIN, APT, VULNERABILITY
- **Also known as:** Lazarus Group, Jade Sleet, Pukchong, UNC4899, Slow Pisces, APT38, BlueNoroff, Stardust Chollima, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC
- **As of:** 2026-09-28

## ATT&CK techniques observed

81 techniques observed across 6 of 6 tracked threats. Tactics: Stealth (formerly Defense Evasion) (14), Discovery (8), Execution (8), Resource Development (8), Command and Control (7), Initial Access (7).

- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 4 of 6 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 6 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 6 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 3 of 6 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 6 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 6 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 6 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 6 tracked threats
- [T1059.007](https://intel.threadlinqs.com/technique/T1059.007) JavaScript — Execution — observed in 2 of 6 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 6 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 6 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 6 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 2 of 6 tracked threats
- [T1195.001](https://intel.threadlinqs.com/technique/T1195.001) Compromise Software Dependencies and Development Tools — Initial Access — observed in 2 of 6 tracked threats
- [T1195.002](https://intel.threadlinqs.com/technique/T1195.002) Compromise Software Supply Chain — Initial Access — observed in 2 of 6 tracked threats

## Tracked threats

- [Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)](https://intel.threadlinqs.com/threat/TL-2026-2657) — HIGH
- [Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse](https://intel.threadlinqs.com/threat/TL-2026-2650) — CRITICAL
- [DPRK Contagious Interview Supply Chain RAT Campaign via npm, PyPI, and Multi-Ecosystem Package Poisoning](https://intel.threadlinqs.com/threat/TL-2026-0332) — HIGH
- [Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat Actors](https://intel.threadlinqs.com/threat/TL-2026-0327) — CRITICAL
- [UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure Compromise](https://intel.threadlinqs.com/threat/TL-2026-0202) — CRITICAL
- [Famous Chollima (DPRK) npm Supply Chain — Pastebin Text Steganography Dead-Drop Resolver, 17 Malicious Packages, Vercel C2 Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-0152) — HIGH

## Related CVEs

1 CVE referenced by tracked TraderTraitor activity.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/TraderTraitor
