TraderTraitor: North Korea’s Crypto Heist Machine

TraderTraitor—also known as Jade Sleet and UNC4899—is one of North Korea’s most aggressive financial APT groups. Responsible for major crypto thefts, including the $1.5B ByBit hack, it targets blockchain developers, exchanges, and fintech firms worldwide.

Moonlight Tiger (APT-C-09, Patchwork, Dropping Elephant): India’s Silent Espionage Arm in the Digital Battlefield

Moonlight Tiger (APT-C-09) is a long-running India-linked cyber-espionage group conducting spearphishing, modular malware campaigns, and intelligence-gathering operations across South and East Asia. Targeting government, defense, academic, and foreign policy institutions, the group continues to evolve through living-off-the-land techniques, custom backdoors, and cloud-enabled C2 infrastructure.

APT37: North Korea’s Active Cyberespionage Group in 2025

APT37 (Famous Chollima) remains one of North Korea’s most active and adaptive cyberespionage groups. This analysis highlights their 2025 evolution—cloud persistence, AI-driven social engineering, new RAT variants, and global targeting across governments, defense, research, and policy organizations.

APT42: Iran’s Shadow Operative in Global Cyberspace

SilverFox APT is rapidly evolving into one of 2025’s most dangerous cyber threat actors. Combining espionage with financial motives, it exploits edge devices, cloud identities, and supply chains to infiltrate governments and enterprises worldwide.