September 23, 2026
PUBLISHED: Sep 23, 2026
On September 22, SlowMist and SentinelOne detailed a fresh campaign by the North Korean group TraderTraitor — the same actor that took $292M from KelpDAO in April through the LayerZero breach. The new victim had nothing to do with crypto: an Indian IT services firm, one infected MacBook belonging to a DevOps engineer. That was enough to open the company's entire cloud.
How it works:
What they take: AWS and GCP tokens, SSH keys, source-control access, browser passwords, terminal history, login.keychain-db and the clipboard — where addresses and seed phrases pass through. Commands arrive over the Nostr relay network, so a plain domain blocklist never sees it.
This continues the scenario that Japan's NPA, the FBI, and Australian and German agencies warned about on September 18: 30,000 infected devices in 100+ countries, 7,000 wallets, $10.7M. The difference is the prize — no longer the wallet on the laptop, but the keys to the cloud and the repos.
What to do:
Got paid from an address you don't know? Screen the sender before that money moves to an exchange: https://t.me/amlconsensus_bot?start=en First check is free.
Sources: SlowMist TI Alert, Sep 22, 2026; SentinelOne Labs "TraderTraitor Backdoors Resurface"; joint advisory NPA/FBI/ASD/BND, Sep 18, 2026.
Consensus of sources · verdict across 35 chains · connection graph and full audit · PDF with QR verification
Open @amlconsensus_bot — 1 free check