Also known as: Jade Sleet, UNC4899, Pukchong
TraderTraitor targets blockchain companies through spear-phishing messages. The group sends these messages to employees, particularly those in system administration or software development roles, on various communication platforms, intended to gain access to these start-up and high-tech companies. TraderTraitor may be the work of operators previously responsible for APT38 activity.
Executive Summary
TraderTraitor, also known as Jade Sleet or Pukchong (UNC4899), is suspected to be linked to APT38 operators targeting blockchain companies. The group employs spear-phishing attacks to compromise system administrators and software developers, aiming to infiltrate high-tech start-ups. While their exact motivations remain unclear, they pose a significant risk to the cryptocurrency sector.
Goals & Targeting
TraderTraitor appears to target sectors with rapid technological advancements, notably blockchain companies, which are often less mature in their cybersecurity practices. The targeting of system administrators and software developers indicates an operational focus on gaining initial access through trusted roles. Their long-term goals likely include data theft, financial gain, or disruption of critical operations, though specific motivations remain unclear.
Enhanced Description
TraderTraitor (Jade Sleet/UNC4899/Pukchong) is a cyber threat actor with suspected ties to APT38 operators. The group primarily targets blockchain companies through sophisticated spear-phishing campaigns. By targeting system administrators and software developers, TraderTraitor seeks to gain unauthorized access to sensitive systems within high-tech organizations. While specifics of their operations are limited, the group's focus on emerging technologies suggests a strategic intent to exploit vulnerabilities in innovative sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TraderTraitor's campaigns are observed targeting system administrators and developers, with a focus on blockchain companies. While no specific campaigns have been confirmed, their operational style suggests a patient and deliberate approach, consistent with state-sponsored or well-organized cybercriminal activity.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis of TraderTraitor is based on limited, but plausible inferences, especially regarding its link to APT38. Further data would enhance confidence in operational details.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics