216.73.217.22

Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators

· Published 18/03/2026 10:49 · Modified 18/03/2026 11:21

Export JSON

Essential information

Published
18/03/2026 10:49
Modified
18/03/2026 11:21
Tags
2026-03-18 beavertail bigsquatrat contagious trader cryptocurrency dprk exfiltration github golangghost invisibleferrett lazarus malware npm ottercookie pylangghost trading bots
Related entities
5 observables, 1 intrusion sets (apt), 20 techniques (mitre), 7 malware, 11 others

Description

The campaign is a sophisticated operation targeting users, attributed to North Korea with high confidence. It involves malicious trading bot projects on that exfiltrate sensitive data and private keys using various techniques, including malicious dependencies. The campaign demonstrates overlaps with known North Korean tactics, particularly those of FAMOUS CHOLLIMA, including the use of , , and Vercel infrastructure, Base64-encoded payload URLs, and anonymizing VPNs for package publishing. The operation represents a shift in tactics, expanding beyond the previous Contagious Interview campaign to target a broader range of users.

External references