Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware


Slow Pisces (aka Jade Sleet, TraderTraitor, PUKCHONG) is a North Korean state-sponsored threat group primarily focused on generating revenue for the DPRK regime, typically by targeting large organizations in the cryptocurrency sector.

This article analyzes their campaign that we believe is connected to recent cryptocurrency heists. In this campaign, Slow Pisces engaged with cryptocurrency developers on LinkedIn, posing as potential employers and sending malware disguised as coding challenges. These challenges require developers to run a compromised project, infecting their systems using malware we have named RN Loader and RN Stealer. The group reportedly stole over $1 billion USD from the cryptocurrency sector in 2023.

Read more…
Source: Palo Alto Unit 42


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • FBI Warns of Scammers Impersonating the IC3

    July 20, 2026

    This Public Service Announcement contains updated information about an ongoing fraud scheme where criminal scammers are impersonating FBI personnel facilitating Internet Crime Complaint Center (IC3) complaints to deceive and revictimize individuals. This scheme combines several exploitation tactics to include the targeting of previous victims, the use of artificial intelligence (AI)-generated videos to create fictitious or misleading promotional ...

  • Hugging Face confirms breach affected internal datasets and credentials

    July 20, 2026

    Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident. In a blog post, the company said a dataset uploaded ...

  • Ernst & Young reveals data breach following hack on support system

    July 20, 2026

    Ernst & Young (EY) has confirmed suffering a cyberattack in which it lost sensitive customer information, including tax data. In a data breach notification letter sent to affected individuals, the firm said that on April 23, 2026, it spotted “anomalous activity” within a third-party platform its IT team uses. This is an IT service management platform ...

  • HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels

    July 20, 2026

    The Group-IB Threat Intelligence team has identified HOLLOWGRAPH, a new malware sample that we attribute, with high confidence, to the Cavern backdoor framework. This malware is one component of a larger toolkit, and it uses the Microsoft Graph API through a compromised Microsoft 365 account observed in Israel to communicate with its operators — a technique ...

  • Healthcare giant Abbott probes two cyber incidents amid extortion claims

    July 20, 2026

    Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims ...

  • Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

    July 17, 2026

    Palo Alto Unit 42 conducted this research in close partnership with Siemens, reflecting their shared commitment to advancing the security and resilience of critical infrastructure. This report details a critical, chained exploit comprising three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) discovered in Siemens ROX II operational technology (OT) switches. Successful exploitation of this chain would allow ...