Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TraderTraitor

Also known as: Jade Sleet, UNC4899, Pukchong

Description

TraderTraitor targets blockchain companies through spear-phishing messages. The group sends these messages to employees, particularly those in system administration or software development roles, on various communication platforms, intended to gain access to these start-up and high-tech companies. TraderTraitor may be the work of operators previously responsible for APT38 activity.

AI Analysis

· 1 week ago

Executive Summary

TraderTraitor, also known as Jade Sleet or Pukchong (UNC4899), is suspected to be linked to APT38 operators targeting blockchain companies. The group employs spear-phishing attacks to compromise system administrators and software developers, aiming to infiltrate high-tech start-ups. While their exact motivations remain unclear, they pose a significant risk to the cryptocurrency sector.

Goals & Targeting

TraderTraitor appears to target sectors with rapid technological advancements, notably blockchain companies, which are often less mature in their cybersecurity practices. The targeting of system administrators and software developers indicates an operational focus on gaining initial access through trusted roles. Their long-term goals likely include data theft, financial gain, or disruption of critical operations, though specific motivations remain unclear.

Enhanced Description

TraderTraitor (Jade Sleet/UNC4899/Pukchong) is a cyber threat actor with suspected ties to APT38 operators. The group primarily targets blockchain companies through sophisticated spear-phishing campaigns. By targeting system administrators and software developers, TraderTraitor seeks to gain unauthorized access to sensitive systems within high-tech organizations. While specifics of their operations are limited, the group's focus on emerging technologies suggests a strategic intent to exploit vulnerabilities in innovative sectors.

Key Capabilities

  • Spear-phishing campaigns
  • Infection via malicious Office documents
  • Undetected persistence mechanisms

MITRE ATT&CK Tactics

Initial Access
Exfiltration

ATT&CK Techniques

T1059.003
T1003
T1566

Software / Tooling

Custom malware likely linked to APT38

Campaigns & Victims

TraderTraitor's campaigns are observed targeting system administrators and developers, with a focus on blockchain companies. While no specific campaigns have been confirmed, their operational style suggests a patient and deliberate approach, consistent with state-sponsored or well-organized cybercriminal activity.

IOC Patterns

  • Spear-phishing emails with malicious Office attachments
  • Lateral movement within internal networks

Recommended Actions

  • Implement advanced phishing detection solutions
  • Conduct regular employee training on identifying spear-phishing attempts
  • Monitor for suspicious network activity related to known APT38 TTPs

Suggested Tags

APT
Blockchain
Spear-Phishing

Confidence Assessment

The analysis of TraderTraitor is based on limited, but plausible inferences, especially regarding its link to APT38. Further data would enhance confidence in operational details.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
APT
Blockchain
Spear-Phishing

Details

Type
Unknown
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.