TraderTraitor is a malware family tracked by ThreatCluster, appearing in 10 threat clusters built from 20 intelligence report mentions.
TraderTraitor is a malware family tracked across 10 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed January 30, 2026; most recent activity June 25, 2026.
On May 5, 2026, Ripple announced it will share internal threat intelligence regarding North Korean hackers with Crypto ISAC, aimed at enhancing security across the cryptocurrency industry. This initiative follows a…
On April 18, 2026, Kelp DAO suffered a significant cyberattack attributed to North Korea's Lazarus Group, resulting in the theft of approximately 116,500 rsETH tokens worth $292 million. The attackers exploited a…
During the G7 Summit in Évian-les-Bains from June 15 to 17, 2026, world leaders focused on North Korean cybercrimes, particularly cryptocurrency thefts. They reported that North Korean hacking groups stole approximately…
A security breach at the Bitcoin DeFi protocol Alex Lab has impacted customers of Shanghai Pudong Development Bank (SPD Bank). The incident, which occurred on June 6, 2025, resulted in the loss of approximately $8.3…
In February 2025, a major hack on the Bybit cryptocurrency exchange resulted in the theft of $1.5 billion in Ethereum. The attack was attributed to the North Korean Lazarus Group's TraderTraitor subunit, exploiting a…
A U.S. federal court has issued a restraining notice preventing Arbitrum DAO from transferring 30,766 ETH (approximately $71.1 million) that was frozen following the Kelp DAO exploit, which resulted in a loss of $292…
On April 18, 2026, Kelp DAO's LayerZero-powered cross-chain bridge was exploited, resulting in the theft of 116,500 rsETH, valued at approximately $293 million. The attacker utilized a forged cross-chain message to…
In May 2026, the cryptocurrency industry experienced losses totaling approximately $68.3 million due to scams and exploits, marking a significant decline of nearly 90% from April's $650 million. The losses stemmed from…
CrowdStrike has reclassified the North Korea-linked intrusion set LABYRINTH CHOLLIMA into three distinct units: GOLDEN CHOLLIMA and PRESSURE CHOLLIMA, which focus on cryptocurrency theft, and the core LABYRINTH CHOLLIMA…
Fireblocks disrupted a North Korea-linked job recruitment scam that targeted crypto firms by using fake interviews and assignments to install malware. The hackers impersonated recruiters and conducted interviews via…
TraderTraitor is a malware family tracked by ThreatCluster, appearing in 10 threat clusters built from 20 intelligence report mentions.
The most recent intelligence report mentioning TraderTraitor on ThreatCluster is dated June 25, 2026. Activity was first observed January 30, 2026, giving a tracked span from then to June 25, 2026.
Across ThreatCluster reporting, TraderTraitor most frequently co-occurs with Apt-38, Diamond Sleet, Golden Chollima, Hidden Cobra, Kimsuky, among 12 tracked related entities.
The most significant recent cluster is “Ripple Shares North Korean Threat Intelligence to Combat Evolving Cyber Attacks” (19 articles · Updated May 5, 2026). TraderTraitor appears across 10 threat clusters in total, listed above with sources.
TraderTraitor appears in 20 intelligence report mentions across 10 deduplicated threat clusters, aggregated from 17,000+ monitored sources.