Lazarus Group: The Complete Guide to North Korea’s Billion-Dollar Hacking Machine

You already know the Lazarus Group’s greatest hits. WannaCry. The Sony Pictures hack. But here is what most of that history misses. In 2025 alone, this single threat actor stole more cryptocurrency than the annual GDP of some small nations, and the biggest heist in that haul never touched a single line of smart contract code. 

For decades, the record for the largest theft in human history belonged to a dictator who physically emptied a bank vault. Then a hacking unit operating out of Pyongyang broke that record from behind a keyboard. 

This guide walks you through who the Lazarus Group really is, how its four operational clusters divide the work, and what three of its most audacious heists teach you about defending your own organization. Let’s get started.


The Motive

Every good threat profile starts with why, because the motive explains everything that happens downstream. So why does a nation-state run the most prolific cybercrime operation on the planet?

A United Nations Panel of Experts report found that malicious cyber activities generate approximately 50% of North Korea’s foreign currency income, with a second member state reporting that 40% of the country’s weapons of mass destruction programs are funded through illicit cyber means. US Deputy National Security Adviser Anne Neuberger has echoed a similar figure, noting that cyber-derived revenue funds roughly half of the country’s nuclear weapons program.

This is not the only nation-state actor turning to cybercrime to fund state objectives, but few blend financial motivation with military intelligence backing quite like Lazarus does. Compare that to a pre-positioning actor like Volt Typhoon, which prioritizes quiet access inside critical infrastructure to enable future disruptive attacks, not immediate financial gain, and the difference in objective becomes obvious fast.

North Korea’s legal export economy is tiny compared to its global trade partners, built mostly on minerals, seafood, and textiles. Its cyber theft operations now generate revenue that dwarfs entire categories of its legitimate trade. Once you understand why Lazarus steals, you stop treating it like a typical espionage-driven nation-state actor and start treating it like a heist team with a government payroll to meet. 

That reframe matters for how you build your threat profile. Most nation-state actors chase intelligence. Lazarus chases cash, and it needs a lot of it, on a schedule. This leads into how they structure their cyber operations.


Lazarus Group Structure: the Reconnaissance General Bureau

Here is a mistake a lot of CTI teams make. They treat “Lazarus” as one signature, one playbook, one detection strategy. But, in reality, Lazarus is not a single hacking team.

Lazarus is an umbrella designation (given by Western CTI) that sits under North Korea’s Reconnaissance General Bureau (RGB), the country’s primary military intelligence agency. Public reporting is not fully consistent on the RGB’s internal org chart (unsurprising, given how little verifiable information exists about North Korean military intelligence), but researchers broadly agree the bureau’s cyber operations run through Bureau 121, and that four operational clusters do the heavy lifting you need to track as an analyst:

  • APT38 (also tracked as BlueNoroff or Stardust Chollima): The financially motivated arm behind bank endpoint compromises, SWIFT manipulation, and automated ATM cash-outs.
  • Andariel (also tracked as Onyx Sleet): Focused on defense and aerospace espionage, and self-funded through ransomware operations like Maui.
  • TraderTraitor (also tracked as Jade Sleet or Slow Pisces): The Web3 and crypto specialists. Multi-sig manipulation, developer social engineering, and the crew most likely to target your development team.
  • Citrine Sleet (also tracked as Gleaming Pisces): Focused on kernel-level rootkits and trojanizing developer tooling, notably through the AppleJeus campaign.

APT38’s SWIFT tradecraft looks nothing like TraderTraitor’s Electron app supply chain approach. If your threat intelligence program writes a single Lazarus playbook instead of four sub-cluster playbooks, you are leaving detection gaps that map directly onto how this actor organizes its own teams. 

Knowing who is pulling the trigger does not explain how this group keeps hitting targets nobody else can touch. To understand that, you need to trace the kill chain this actor has followed across a decade of operations.


The Evolution of the Lazarus Group

Trace Lazarus’s history and a clear pattern emerges: destruction, then disruption, then extraction.

  • 2009, Operation Troy: Unsophisticated DDoS attacks against South Korean and US government portals.
  • 2013, DarkSeoul: Wiper malware bricks tens of thousands of machines at South Korean banks.
  • 2014, the Sony Pictures hack: Corporate sabotage as political retaliation, carried out under the Guardians of Peace front.
  • 2016, the Bangladesh Bank heist: The inflection point where Lazarus stops being a disruption actor and becomes a financial crime syndicate. More on this one below.
  • 2017, WannaCry: A global ransomware worm that hit roughly 200,000 systems across 150 countries, including the UK’s National Health Service.
  • 2017 to 2018: Early crypto attacks establish the theft model that now dominates this group’s operations.
  • 2022, Ronin Network: Roughly $625 million stolen from the sidechain behind the Axie Infinity game.
  • 2023, the 3CX attack: A cascading supply chain compromise. Also covered in detail below.
  • 2024, DMM Bitcoin and WazirX: $308 million and $235 million, respectively, taken from two separate exchanges.
  • 2025, Bybit: A $1.5 billion heist on Ethereum. The largest cryptocurrency theft in history, executed against a platform running multi-signature wallets and hardware key approval, defenses everyone assumed were close to unbreakable.

Chainalysis reports that North Korean hackers stole $2.02 billion in cryptocurrency in 2025 alone, a 51% year-over-year increase, pushing their all-time total to $6.75 billion despite fewer overall attacks. And the pace hasn’t slowed. TRM Labs found that North Korean hacking groups were responsible for an estimated 76% of global cryptocurrency thefts in the first four months of 2026 alone, driven by just two major attacks.

The pattern tells you what they steal and roughly when. It does not tell you how they get past defenses that are supposed to be unbreakable. For that, here are three case files that show how these operations function.

Case File 1: The Bangladesh Bank Heist

The intrusion chain starts small: a spear phishing email lands on a bank employee’s workstation. From there, the attackers move laterally to the terminal with SWIFT access.

Then comes the signature move. Malware patches active memory, replacing a conditional jump instruction with a no-operation instruction (a “nop slide”), forcing cryptographic and database verification checks to register as successful regardless of the actual system state. 

The attackers also intercepted the printer spooler queue, deleting fraudulent transaction logs before they were ever printed.

The hackers used the SWIFT network to instruct Bangladesh Bank to issue transfer orders totaling roughly $951 million, of which $101 million was authorized and paid from the bank’s account at the Federal Reserve Bank of New York. Around $81 million of that reached accounts in the Philippines and was laundered through casinos before most of it could be recovered.

The difference between an $81 million loss and a $1 billion catastrophe came down to a single misspelling: Deutsche Bank grew suspicious after noticing a typo where “foundation” had been misspelled as “fandation,” which triggered a manual review and froze the remaining fraudulent transfers.

MITRE ATT&CK Mapping
  • Phishing (T1566) for initial access
  • Valid Accounts (T1078) for the SWIFT terminal
  • Process Injection (T1055) for the memory patch
  • Indicator Removal (T1070) for the deleted printer logs
Detection Opportunity

Process memory integrity monitoring on SWIFT-adjacent terminal hosts would have flagged the nop patch. Auditing the printer spooler separately from the logs it produces would have caught the deletion before it became a blind spot.

Case File 2: The 3CX Attack

This is the first confirmed case of a cascading, double supply chain attack. One vendor compromise enabled a second vendor compromise.

A 3CX employee downloaded and executed a trojanized, end-of-life version of the X_Trader trading software from Trading Technologies, which gave the threat cluster tracked by MITRE as UNC4736 access to the 3CX environment. From there, the attackers compromised the Windows and macOS build environments used to distribute the 3CX desktop application to its customers.

Trace the technical chain, and it gets stranger. The trojanized installer, signed with a valid certificate, drops a DLL that runs a tool called SIGFLIP. SIGFLIP extracts an embedded payload from a signed file without invalidating that file’s signature, decrypts it with a hardcoded RC4 key, and reflectively loads a backdoor that runs entirely in memory. No disk artifacts to catch.

From the compromised developer’s workstation, the attackers harvested VPN credentials and pivoted into 3CX’s build pipeline. Every customer who downloaded a legitimately signed 3CX update after that point walked away with a backdoor they never asked for.

MITRE ATT&CK Mapping
  • Supply Chain Compromise (T1195)
  • DLL Search Order Hijacking (T1574.001)
  • Obfuscated Files or Information (T1027)
Detection Opportunity

Behavioral detection on signed binaries would have caught this one. SIGFLIP’s entire purpose is bypassing signature trust, so if your EDR allows lists on signature validity alone, this class of attack is invisible to you. You need to scan memory, not just check signatures. 

Case File 3: The Bybit Heist

This is the heist where Lazarus made three trained signers at one of the world’s largest exchanges physically watch a fake transaction approve itself. No smart contract was exploited. The technical signature here is client-side interface poisoning.

A developer machine tied to the Safe{Wallet} multisig platform was compromised, and malicious JavaScript was injected into the front-end interface with a conditional trigger that only activated when the transaction source matched Bybit’s specific cold storage contract addresses. When Bybit’s three required signers loaded that interface, their screens displayed a routine internal transfer.

In the background, the JavaScript altered the destination address sent to their hardware wallets. They signed exactly what they saw, and what they saw was a lie. The resulting signatures were cryptographically valid, authorizing a transaction the signers never intended to approve.

Blockchain analysis firms, including Elliptic and Arkham Intelligence, traced the stolen crypto as it moved to various accounts and was swiftly offloaded, in a theft that far surpassed all previous crypto thefts on record. The FBI later confirmed North Korea stole approximately $1.5 billion USD in virtual assets from Bybit, attributing the activity to a cluster it calls TraderTraitor.

The smart contract executed flawlessly. The vulnerability was never in the code. It was in the trust between what a human sees on screen and what a human actually signs.

MITRE ATT&CK Mapping
  • Supply Chain Compromise (T1195)
  • Browser Session Hijacking (T1185)
  • Transmitted Data Manipulation (T1565.001) of the transaction payload
Detection Opportunity

Out-of-band transaction verification is the control you need here. If your signing process trusts whatever renders on a potentially compromised browser, hardware key approval provides zero actual security. Independent verification of the raw transaction payload, not the interface’s representation of it, is what would have stopped this. 

Three heists. Three completely different kill chains. Memory patching, signature-preserving supply chain poisoning, and client-side rendering manipulation. If your team is hunting for one Lazarus signature, you are going to miss the other two. 

Notice, too, how far up the pyramid of pain these detection opportunities sit. None of them rely on a hash or an IP address, which is exactly why they still work years after the malware itself was burned.

That’s enough theory. Let’s explore how you can hunt for these threats in your environment!


Four Threat Hunts to Find the Lazarus Group

Here are threat hunts you can run today to track down this activity in your environment. If you are new to structuring hunts this way, our guide to threat hunting with Velociraptor is a good place to build the underlying process.

Hunt #1 – TraderTraitor

In Electron-based crypto apps, watch for an update-check callback pattern, bundled via webpack, that makes an HTTP POST request to a remote PHP endpoint, decrypts an AES-256 payload into the OS temp directory, and executes it via a child process. That execution chain is your rule. Signature-based tooling never sees it, so focus on parent-child process relationships instead.

Hunt #2 – Bangladesh Bank pattern

Monitor for unexpected memory patches in SWIFT-adjacent applications and any anomalies in printer or logging activity tied to financial systems. This is a known playbook now, which means it is still being reused, not retired.

Hunt #3 – 3CX pattern

Track certificates that are valid but recently expired on installers, reflective DLL loading with no on-disk artifacts, and any process establishing command-and-control traffic over what looks like a legitimate vendor update path. A valid signature is a data point, not a trust boundary.

Hunt #4 – Insider Threats

Build a behavioral baseline for new hire devices in their first 72 hours. Watch for unexpected peripheral connections, unusual child process spawning, and any mismatch between a worker’s claimed geolocation and their payroll address.

That fourth hunt is not a hypothetical. Increasingly, these attacks are supported by someone already on the inside. This is where the Lazarus Group is heading in 2026 and beyond.


The Lazarus Group’s Strategic Shift

As perimeter defenses hardened, Lazarus did not escalate technically. It pivoted to identity.

The Reconnaissance General Bureau now runs an organized remote IT worker program, which Mandiant tracks as UNC5267. This program made mainstream headlines when Christina Chapman pleaded guilty to wire fraud, money laundering, and identity theft after the FBI discovered she was an instrumental part of a wider campaign to get North Korean operatives hired in six-figure IT roles at prominent companies.

According to the Department of Justice, she hosted a laptop farm from her Arizona home that let North Korean operatives connect with US local IP addresses, helping them land jobs at more than 300 American companies, including Fortune 500 corporations, generating over $17 million in illicit revenue. She was sentenced to 8.5 years in prison in 2025.

One Fortune-level brand unknowingly paid a fabricated identity a five-figure salary before anyone noticed. Lazarus increasingly does not need a zero-day. It just needs a résumé and a stolen identity. 

This is a threat actor’s clearest possible statement of intent: bypass the perimeter entirely by becoming a trusted insider. Lazarus is not alone in leaning on social engineering and identity abuse either. Groups like Scattered Spider have shown the same shift toward exploiting people instead of code, which means insider risk deserves a permanent seat in your threat model, not a one-off mention.

Our read: line up the pattern and the next move is not hard to predict. Each phase of Lazarus’s evolution targeted whatever defense the previous phase made obsolete: wipers until endpoint detection caught up, SWIFT fraud until transaction monitoring caught up, signed supply chain compromises until behavioral detection caught up. 

The IT worker scheme applies that logic to hiring, one of the least monitored attack surfaces most organizations have. If the pattern holds, expect the next shift toward whatever identity gap lacks a detection story, likely contractor and vendor onboarding, which typically gets even less scrutiny than direct employment does.

You now have the framework CTI teams use to track this actor: the four clusters, the three kill chains, and the four hunts built to catch them. Put even one hunt into rotation this week, and you are already ahead of where most teams are with Lazarus. Good luck out there.

Frequently Asked Questions

What is the Lazarus Group?

The Lazarus Group is a North Korean state-sponsored threat actor operating under the Reconnaissance General Bureau. It functions as an umbrella designation for several operational clusters, including APT38, Andariel, TraderTraitor, and Citrine Sleet, that specialize in financial theft, espionage, and supply chain attacks.

How Much Money Has the Lazarus Group Stolen?

North Korean hackers linked to Lazarus stole $2.02 billion in cryptocurrency in 2025 alone, pushing their cumulative total since 2017 to roughly $6.75 billion. That figure continues to climb through 2026.

What Was the Largest Lazarus Group Heist?

The February 2025 Bybit hack, in which roughly $1.5 billion in Ethereum was stolen, is the largest cryptocurrency heist in history.

Is Lazarus the Same as APT38?

Not exactly. APT38 (also known as BlueNoroff) is one of several operational clusters that fall under the broader Lazarus umbrella, alongside Andariel, TraderTraitor, and Citrine Sleet. Each cluster has a distinct specialty and tradecraft.

How Does the Lazarus Group Launder Stolen Cryptocurrency?

Lazarus typically converts stolen assets into Bitcoin and other cryptocurrencies, then disperses them across thousands of blockchain addresses, cross-chain bridges, and mixing services to obscure the money trail before eventually converting proceeds to fiat currency.