Lazarus Group
North Korean state-sponsored (RGB) · Financial theft / espionage / sanctions evasion
Tactics, Techniques & Procedures (TTPs)
- TraderTraitor LinkedIn fake job offer social engineering
- Trojanised developer tools, npm packages, and GitHub repositories
- Cryptocurrency exchange hot wallet targeting
- SWIFT financial messaging system compromise
- AppleJeus macOS malware for crypto platforms
- Supply chain software poisoning
Known Targets
Analyst Notes
Operates under North Korea's Reconnaissance General Bureau (RGB). Estimated $3B+ stolen in cryptocurrency since 2017, used to fund DPRK weapons programmes. WannaCry 2017 attributed to Lazarus. The Bybit exchange theft in February 2025 — $1.5 billion — is the largest single cryptocurrency theft on record, executed via a compromised Safe{Wallet} developer.
Also Known As
Intelligence Reports
Lazarus Burned a Windows Kernel Zero-Day for Six Weeks Targeting Defence and Aerospace
CVE-2026-68820, a use-after-free in Windows AFD.sys patched on August 11 Patch Tuesday, was actively exploited by North Korea's Lazarus Group since early July in a fresh Operation Dream Job wave targeting defence, aerospace, aviation, and UAV firms across Europe and India. The attack chain drops the FudModule rootkit and a newly identified modular backdoor named Troy.
Lazarus Group Extends Cryptocurrency Targeting to UK Exchanges and Law Firm Custodians
North Korea's Lazarus Group has extended its cryptocurrency theft operations to UK-regulated digital asset exchanges and the law firms that provide custody and compliance services to crypto clients -- combining financial theft with intelligence collection.