---
title: "TraderTraitor: Targeted Attack on Blockchain Organizations | DuoCircle"
description: "Recently, the North Korean cyberattack group, Lazarus, has been launching cyberattacks targeted at stealing cryptocurrencies laundered to North Korea."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/email-security/tradertraitor-targeted-attack-on-blockchain-organizations/"
---

Quick Answer

TraderTraitor is a campaign attributed to North Korea's Lazarus Group (also tracked as APT38, BlueNoroff, Stardust Chollima) targeting blockchain firms, cryptocurrency exchanges, NFT projects, and crypto-game studios since 2020\. The FBI, CISA, and Treasury issued a joint advisory in April 2022\. The technique: spear phishing employees with fake high-paying job offers, leading the target to download trojanized cryptocurrency or trading applications (variants tracked as TraderTraitor) that establish persistence and exfiltrate wallet keys and exchange credentials. Stolen funds get laundered through mixers and routed to North Korea, helping fund sanctions evasion and weapons programs. Defenses for crypto-adjacent firms: MFA (preferably FIDO2 hardware) on every wallet, exchange, and admin account; application allowlisting so unsigned binaries cannot execute; endpoint detection on developer machines; recurring training that flags unsolicited recruiter messages with downloads; and treasury controls requiring multi-party approval for large transfers.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Femail-security%2Ftradertraitor-targeted-attack-on-blockchain-organizations%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=TraderTraitor%3A%20Targeted%20Attack%20on%20Blockchain%20Organizations&url=undefined%2Fblog%2Femail-security%2Ftradertraitor-targeted-attack-on-blockchain-organizations%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Femail-security%2Ftradertraitor-targeted-attack-on-blockchain-organizations%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Femail-security%2Ftradertraitor-targeted-attack-on-blockchain-organizations%2F&title=TraderTraitor%3A%20Targeted%20Attack%20on%20Blockchain%20Organizations "Share on Reddit") [ ](mailto:?subject=TraderTraitor%3A%20Targeted%20Attack%20on%20Blockchain%20Organizations&body=Check out this article: undefined%2Fblog%2Femail-security%2Ftradertraitor-targeted-attack-on-blockchain-organizations%2F "Share via Email") 

![Blockchain organizations](https://media.mailhop.org/duocircle/images/2022/05/sendgrid-alternative-4738-1.jpg) 

Recently, the North Korean cyberattack group, Lazarus, has been launching cyberattacks targeted at **stealing cryptocurrencies** laundered to North Korea. These attacks have been going on since 2020; more recently, they have [alerted](https://www.ic3.gov/Media/News/2022/220418.pdf) the U.S. government, FBI (Federal Bureau of Investigation), and CISA (Cybersecurity and Infrastructure Security Agency). Here’s everything you need to know about the cybersecurity threat.

## The Attack By the APT Group

The latest attack scheme launched by the North Korean threat group Lazarus (also known as APT38, BlueNoroff, Stardust Chollima, etc.) _targets blockchain users and organizations_. Cryptocurrency exchanges, and even NFTs, are activities to which the group is sensitive. Targeting cryptocurrency traders, crypto investors, crypto-based video games, and crypto holders, the group has siphoned large amounts in [cryptocurrencies](/content/email-security-services/email-security-in-cryptography). By April 2022, the group had drained significant amounts of crypto to North Korea.

## The Techniques To Be Wary Of

After the [Great Resignation](https://en.wikipedia.org/wiki/Great%5FResignation), job offers have been one way to attract unsuspecting victims to click on suspicious links. The Lazarus Group also uses this method to lure victims. They send emails to employees of organizations involved in crypto, disguising the attack as an _attempt to hire them for high-paying jobs_. The employees are then suggested to download a file masquerading as malware, collectively named the TraderTraitor by the U.S. government.

The TraderTraitor is a series of **applications and websites** that look real but are entirely controlled by cyberattackers. They are designed as a crypto-based application or website that steals the victims’ information to drain money from their accounts. Such threats will require extreme vigilance of the victim so that they do not get lured into the cybercriminals’ almost clear but carefully devised plan.

Some of the malware **successfully detected** and recognized so far are:

- DAFOM (dafom\[.\]dev)
- TokenAIS (tokenais\[.\]com)
- CryptAIS (cryptais\[.\]com)
- AlticGO (alticgo\[.\]com)
- Esilet (esilet\[.\]com), and
- CreAI Deck (creaideck\[.\]com)

DAFOM is designed to look like a portfolio application for cryptocurrency and previously came with an Apple digital signature issued for the Apple Developer Team W58CYKFH67\. This signature gave the application the guarantee of authenticity. There was even a section to file complaints regarding application bugs. Apple revoked the signature, and metadata related to the bug report section previously stored on the GitHub repository has been erased. However, this case is sufficient for anyone to understand how easily victims were lured into the traps and lost money to an application that seemed **genuine**.

TokenAIS and CryptAIS are designed to create a portfolio concerning AI-based trading for crypto. The cyber attackers carefully develop these apps to store any information you enter.

[![advanced phishing strategies](https://media.mailhop.org/duocircle/images/2022/05/smtp-email-4625.jpg)](https://media.mailhop.org/duocircle/images/2022/05/smtp-email-4625.jpg)

## Defense in The Face of Threat

Although the existence of such [advanced phishing strategies](/email-security/impending-cybersecurity-threats-to-businesses-in-2022-and-beyond/) can be overwhelming, the FBI, the U.S. government, and CISA have come up with some simple methods to help you steer clear of malicious actors:

- **Advanced Defense Strategies:** [Advanced defense strategies](/advanced-threat-defense) such as using a segmented network to prevent lateral movement limiting attack surface in an organization can help keep information systems secure in the event of a cyber attack.
- **Regular Patching of Vulnerabilities:** Routine security evaluation of the organization can help identify any threats and vulnerabilities in the organizational systems. These vulnerabilities must then be patched at the earliest.
- **Extra Precautionary Steps, Such as MFA:** Adopt Multi Factor Authentication (MFA), even for internal tools and applications. The Lazarus Group uses the victim’s credentials, emails, and private business accounts to attack. Routine changes of passwords can also ensure safety.
- **Employee Training:** [Train your employees](/phishing-awareness-training) about cybersecurity hygiene and enforce healthy cyber practices. Some of the standard procedures that the employees can learn are not clicking on links that seem suspicious, not revealing their passwords, and not sharing their MFA codes with others. Regular and updated courses will help both the organization and the individual.
- **Email and Domain Awareness:** Most [phishing attacks](/resources/identify-and-neutralize-phishing-attacks) are centered around current affairs or emails that might look genuine but be phony. Social engineering attacks can also be themed around social issues that might invoke the victim’s empathy. It is essential to spread awareness that the victim should carefully check the authenticity of the email and website before clicking on the link in such cases.
- **Take Care When Downloading Applications and Freeware Software:** The applications that the Lazarus Group suggests in their attack are open source. Hence, it is essential to take extra precautions when downloading from third-party stores. Open-source applications that are not published on official app stores and websites that your cyber security system deems harmful might be a gateway for malicious actors to get across the malware.

[![anti-malware tools](https://media.mailhop.org/duocircle/images/2022/05/hosted-email-server-6735.jpg)](https://media.mailhop.org/duocircle/images/2022/05/hosted-email-server-6735.jpg)

## Final Words

The recent North Korean state-sponsored attack demands high vigilance and awareness levels at the individual as well as the organizational level. Following the guidelines mentioned above should serve as the **first line of defense** against the majority of the threats that these threat actors post. However, to be on the safer side, anti-phishing and anti-malware tools must also be adopted to protect the interests of your employees and your customers.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Ftradertraitor-targeted-attack-on-blockchain-organizations%2F) [ ](https://twitter.com/intent/tweet?text=TraderTraitor%3A%20Targeted%20Attack%20on%20Blockchain%20Organizations&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Ftradertraitor-targeted-attack-on-blockchain-organizations%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Ftradertraitor-targeted-attack-on-blockchain-organizations%2F) Copy 

Related Articles

- [  BIMI in 2026: What the Certificate Authority Does, and What Your DMARC Tool Does Email Security ](/blog/bimi-2026-what-the-ca-does-what-your-dmarc-tool-does/)
- [ ![Designing A Custom Dkim Architecture For High-Volume Email Senders](https://media.mailhop.org/duocircle/images/2026/04/buy-smtp-1290.jpg)  Designing A Custom Dkim Architecture For High-Volume Email Senders Email Security ](/blog/designing-custom-dkim-architecture-for-high-volume-email-senders/)
- [ ![DMARC, SPF, and DKIM](https://media.mailhop.org/duocircle/images/2026/04/spf-record-4526.jpg)  DMARC, SPF, and DKIM in 2026: Why Email Authentication Is Now a Regulatory Requirement, Not Just a Best Practice Email Security ](/blog/dmarc-spf-dkim-2026-email-authentication-regulatory-requirement-best-practice/)
- [ ![Email Monitoring Tools](https://media.mailhop.org/duocircle/images/2026/05/spf-validator-6720.jpg)  Email Monitoring Tools: A Complete Guide to Protecting Your Email Ecosystem Email Security ](/blog/email-monitoring-tools-guide-protecting-your-email-ecosystem-security/)

## Related Articles

[  Email Security 8m  BIMI in 2026: What the Certificate Authority Does, and What Your DMARC Tool Does  May 5, 2026 ](/blog/bimi-2026-what-the-ca-does-what-your-dmarc-tool-does/)[  Email Security 8m  Designing A Custom Dkim Architecture For High-Volume Email Senders  Apr 28, 2026 ](/blog/designing-custom-dkim-architecture-for-high-volume-email-senders/)[  Email Security 12m  DMARC, SPF, and DKIM in 2026: Why Email Authentication Is Now a Regulatory Requirement, Not Just a Best Practice  Apr 29, 2026 ](/blog/dmarc-spf-dkim-2026-email-authentication-regulatory-requirement-best-practice/)[  Email Security 5m  Email Monitoring Tools: A Complete Guide to Protecting Your Email Ecosystem  May 7, 2026 ](/blog/email-monitoring-tools-guide-protecting-your-email-ecosystem-security/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"TraderTraitor: Targeted Attack on Blockchain Organizations","description":"Recently, the North Korean cyberattack group, Lazarus, has been launching cyberattacks targeted at stealing cryptocurrencies laundered to North Korea.","url":"https://www.duocircle.com/blog/email-security/tradertraitor-targeted-attack-on-blockchain-organizations/","datePublished":"2022-05-03T13:30:57.000Z","dateModified":"2025-05-24T16:33:32.000Z","dateCreated":"2022-05-03T13:30:57.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/tradertraitor-targeted-attack-on-blockchain-organizations/"},"articleSection":"email-security","keywords":"","wordCount":818,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/05/sendgrid-alternative-4738-1.jpg","caption":"Blockchain organizations","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Email Security"},{"@type":"ListItem","position":3,"name":"TraderTraitor: Targeted Attack on Blockchain Organizations","item":"https://www.duocircle.com/blog/email-security/tradertraitor-targeted-attack-on-blockchain-organizations/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Email Security","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"TraderTraitor: Targeted Attack on Blockchain Organizations","item":"https://www.duocircle.com/blog/email-security/tradertraitor-targeted-attack-on-blockchain-organizations/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"TraderTraitor: Targeted Attack on Blockchain Organizations","description":"Recently, the North Korean cyberattack group, Lazarus, has been launching cyberattacks targeted at stealing cryptocurrencies laundered to North Korea.","url":"https://www.duocircle.com/blog/email-security/tradertraitor-targeted-attack-on-blockchain-organizations/","datePublished":"2022-05-03T13:30:57.000Z","dateModified":"2025-05-24T16:33:32.000Z","dateCreated":"2022-05-03T13:30:57.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/tradertraitor-targeted-attack-on-blockchain-organizations/"},"articleSection":"email-security","keywords":"","wordCount":818,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/05/sendgrid-alternative-4738-1.jpg","caption":"Blockchain organizations","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
