September 23, 2026

A "take-home test" at a job interview took the keys. The victim wasn't a crypto project

PUBLISHED: Sep 23, 2026

On September 22, SlowMist and SentinelOne detailed a fresh campaign by the North Korean group TraderTraitor — the same actor that took $292M from KelpDAO in April through the LayerZero breach. The new victim had nothing to do with crypto: an Indian IT services firm, one infected MacBook belonging to a DevOps engineer. That was enough to open the company's entire cloud.

How it works:

What they take: AWS and GCP tokens, SSH keys, source-control access, browser passwords, terminal history, login.keychain-db and the clipboard — where addresses and seed phrases pass through. Commands arrive over the Nostr relay network, so a plain domain blocklist never sees it.

This continues the scenario that Japan's NPA, the FBI, and Australian and German agencies warned about on September 18: 30,000 infected devices in 100+ countries, 7,000 wallets, $10.7M. The difference is the prize — no longer the wallet on the laptop, but the keys to the cloud and the repos.

What to do:

Got paid from an address you don't know? Screen the sender before that money moves to an exchange: https://t.me/amlconsensus_bot?start=en First check is free.

Sources: SlowMist TI Alert, Sep 22, 2026; SentinelOne Labs "TraderTraitor Backdoors Resurface"; joint advisory NPA/FBI/ASD/BND, Sep 18, 2026.

Screen your counterparty now

Consensus of sources · verdict across 35 chains · connection graph and full audit · PDF with QR verification

Open @amlconsensus_bot — 1 free check