TraderTraitor Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
20
occurrences
First Seen
January 30, 2026
Last Seen
June 25, 2026

TraderTraitor is a malware family tracked by ThreatCluster, appearing in 10 threat clusters built from 20 intelligence report mentions.

TraderTraitor is a malware family tracked across 10 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed January 30, 2026; most recent activity June 25, 2026.

Related Threat Clusters

  • Ripple Shares North Korean Threat Intelligence to Combat Evolving Cyber Attacks

    On May 5, 2026, Ripple announced it will share internal threat intelligence regarding North Korean hackers with Crypto ISAC, aimed at enhancing security across the cryptocurrency industry. This initiative follows a…

    19 articles · Updated May 5, 2026
  • Kelp DAO and Aave Resume Operations After $292 Million Exploit

    On April 18, 2026, Kelp DAO suffered a significant cyberattack attributed to North Korea's Lazarus Group, resulting in the theft of approximately 116,500 rsETH tokens worth $292 million. The attackers exploited a…

    9 articles · Updated May 14, 2026
  • G7 Leaders Address North Korean Cybercrime and Cryptocurrency Theft

    During the G7 Summit in Évian-les-Bains from June 15 to 17, 2026, world leaders focused on North Korean cybercrimes, particularly cryptocurrency thefts. They reported that North Korean hacking groups stole approximately…

    5 articles · Updated June 17, 2026
  • Alex Lab Hack Affects SPD Bank Clients After $8.3M Exploit

    A security breach at the Bitcoin DeFi protocol Alex Lab has impacted customers of Shanghai Pudong Development Bank (SPD Bank). The incident, which occurred on June 6, 2025, resulted in the loss of approximately $8.3…

    6 articles · Updated April 30, 2026
  • Bybit Hack: $1.5 Billion Theft by North Korean Hackers

    In February 2025, a major hack on the Bybit cryptocurrency exchange resulted in the theft of $1.5 billion in Ethereum. The attack was attributed to the North Korean Lazarus Group's TraderTraitor subunit, exploiting a…

    2 articles · Updated June 9, 2026
  • Court Freezes $71 Million in Ethereum Linked to North Korea's Lazarus Group

    A U.S. federal court has issued a restraining notice preventing Arbitrum DAO from transferring 30,766 ETH (approximately $71.1 million) that was frozen following the Kelp DAO exploit, which resulted in a loss of $292…

    63 articles · Updated May 3, 2026
  • Kelp DAO Exploit: $293 Million Drain Triggers DeFi Contagion

    On April 18, 2026, Kelp DAO's LayerZero-powered cross-chain bridge was exploited, resulting in the theft of 116,500 rsETH, valued at approximately $293 million. The attacker utilized a forged cross-chain message to…

    187 articles · Updated April 18, 2026
  • Crypto Sector Suffers $68.3M Losses from Scams in May 2026

    In May 2026, the cryptocurrency industry experienced losses totaling approximately $68.3 million due to scams and exploits, marking a significant decline of nearly 90% from April's $650 million. The losses stemmed from…

    58 articles · Updated June 1, 2026
  • CrowdStrike Identifies Three Splinter Groups from LABYRINTH CHOLLIMA

    CrowdStrike has reclassified the North Korea-linked intrusion set LABYRINTH CHOLLIMA into three distinct units: GOLDEN CHOLLIMA and PRESSURE CHOLLIMA, which focus on cryptocurrency theft, and the core LABYRINTH CHOLLIMA…

    6 articles · Updated January 30, 2026
  • North Korea Hackers Use Job Scams to Target Crypto Firms

    Fireblocks disrupted a North Korea-linked job recruitment scam that targeted crypto firms by using fake interviews and assignments to install malware. The hackers impersonated recruiters and conducted interviews via…

    307 articles · Updated January 31, 2026

Recent Intelligence Reports

  • $2B Bybit hack linked to North Korea, Iran involvement unconfirmed — Cryptobriefing · June 25, 2026
  • What did G7 leaders declare regarding North Korean cryptocurrency thefts and cybercrimes ... — Weex · June 17, 2026
  • Bybit Hack Strategic Risks Overlooking Crypto Exchange Security 2026 2512 — www.ainvest.com · June 9, 2026
  • Aave transfers first 25000 rsETH tranche to LayerZero adapter as Kelp reopens cross — Mexc · May 14, 2026
  • Ripple shares North Korea — Theblock.Co · May 5, 2026
  • Ripple shares North Korea — Theblock.Co · May 5, 2026
  • Frozen Kelp DAO ETH on Arbitrum Sparks Dispute Over DPRK Claims — Coinedition · May 4, 2026
  • Alex Lab hack reportedly hits SPD Bank clients after earlier $8.3M exploit — Mexc.Co · April 30, 2026

Frequently asked questions

What is TraderTraitor?

TraderTraitor is a malware family tracked by ThreatCluster, appearing in 10 threat clusters built from 20 intelligence report mentions.

Is TraderTraitor still active?

The most recent intelligence report mentioning TraderTraitor on ThreatCluster is dated June 25, 2026. Activity was first observed January 30, 2026, giving a tracked span from then to June 25, 2026.

What is TraderTraitor associated with?

Across ThreatCluster reporting, TraderTraitor most frequently co-occurs with Apt-38, Diamond Sleet, Golden Chollima, Hidden Cobra, Kimsuky, among 12 tracked related entities.

What are the latest developments involving TraderTraitor?

The most significant recent cluster is “Ripple Shares North Korean Threat Intelligence to Combat Evolving Cyber Attacks” (19 articles · Updated May 5, 2026). TraderTraitor appears across 10 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on TraderTraitor?

TraderTraitor appears in 20 intelligence report mentions across 10 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown