Lazarus Group
The most widely used name for North Korea's state-sponsored hacking apparatus, run under its Reconnaissance General Bureau. Blamed for the Sony hack, the Bangladesh Bank SWIFT heist, WannaCry, and — since ~2017 — many of the largest crypto thefts ever. Chainalysis puts DPRK's cumulative crypto haul near $6.75B, used to fund the regime's weapons programs.
Also known as: Lazarus Group, Hidden Cobra, APT38, BlueNoroff, Andariel, Guardians of Peace, ZINC, TEMP.Hermit, Diamond Sleet, Reconnaissance General Bureau
On attribution: "Lazarus Group" is a label applied by governments and security firms to overlapping North Korean state hacking units. Attributions below are those of the cited authorities (FBI, U.S. Treasury, DOJ, UN) and analytics firms (Chainalysis, Elliptic, Mandiant); cyber-attribution is rarely 100% certain. See the linked case entries for incident-specific findings.
Overview
Lazarus Group is the most common name for a set of state-sponsored hacking units operated by North Korea's military-intelligence agency, the Reconnaissance General Bureau (RGB). When the U.S. Treasury sanctioned it in September 2019, it listed numerous aliases used across the security industry, including Hidden Cobra, Guardians of Peace, APT-C-26, Group 77, Office 91, ZINC, and TEMP.Hermit. The same action sanctioned two RGB sub-groups, Bluenoroff (a.k.a. APT38) and Andariel. [1]
Structure and sub-units
Researchers track several overlapping clusters under the Lazarus/RGB umbrella:
- Bluenoroff / APT38 — focused on financial theft (banks, exchanges). [1][2]
- Andariel — espionage plus revenue generation. [1]
- TraderTraitor (Jade Sleet / UNC4899) — recent exchange mega-thefts (see its own entry).
- Contagious Interview / UNC4736 (AppleJeus, Citrine Sleet) — fake-recruiter malware (see its own entry).
A February 2021 U.S. indictment alleged these RGB units operated as "a single conspiracy." [2]
Early operations (pre-crypto)
Lazarus is linked to a string of landmark intrusions: the 2014 Sony Pictures Entertainment hack; the February 2016 Bangladesh Bank heist, in which attackers used compromised SWIFT credentials to issue 35 fraudulent transfer requests totaling ~$951 million (most were blocked, but ~$81 million was taken and laundered through Philippine casinos); and the 2017 WannaCry ransomware outbreak. The Bangladesh heist marked a turning point — a nation-state stealing for profit. [2][6]
Pivot to cryptocurrency
From around 2017, Lazarus increasingly targeted cryptocurrency. Campaigns such as "AppleJeus" distributed trojanized trading apps, and the group went after exchanges, cross-chain bridges, DeFi protocols, wallet software, and individual holders. U.S. and UN officials assess the proceeds fund North Korea's nuclear-weapons and ballistic-missile programs.
Linked scams & cases
- Upbit hackAttributed actorExchanges & platformsIn November 2019, 342,000 ETH (~$41.5M at the time) was stolen from South Korean exchange Upbit. In November 2024 South Korea's National Police Agency officially attributed the theft to North Korea's Lazarus and Andariel groups — its first such attribution of an exchange hack.
- Phemex hackAttributed actor (on-chain analysis)Exchanges & platformsIn January 2025, the Singapore-based exchange Phemex had its hot wallets drained across 16 blockchains, with losses estimated at $73–85M. On-chain investigators (ZachXBT, Arkham) tied it to North Korea's Lazarus Group, later linking it directly to the Bybit and BingX hacks via commingled funds.
Sources (8)
- Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups — U.S. Department of the Treasury
- 3 North Korean Military Hackers Indicted in Wide-Ranging Scheme (>$1.3B) — U.S. DOJ / Secret Service
- North Korea Responsible for $1.5 Billion Bybit Hack — U.S. FBI
- $2.2 Billion Stolen in Crypto in 2024 (DPRK $1.34B) — Chainalysis
- 2025 Crypto Theft Reaches $3.4 Billion (DPRK cumulative ~$6.75B) — Chainalysis
- The Lazarus heist: How North Korea almost pulled off a billion-dollar hack — BBC News
- North Korea-linked Atomic Wallet heist tops $100 million — Elliptic
- Lazarus Group Pulled Off 2020's Biggest Exchange Hack (KuCoin) — Chainalysis
See also
- 2025 Czech government Bitcoin scandalOtherA political-corruption scandal in which the Czech Ministry of Justice, under minister Pavel Blažek, accepted a donation of 468 bitcoin (~$45M) in early 2025 from Tomáš Jiříkovský, a convicted darknet/drug figure, then sold part of it. After Deník N revealed the deal in May 2025, Blažek resigned, a criminal money-laundering investigation followed, and the government narrowly survived a no-confidence vote.
- Ledger Connect Kit hackWallet drainersA December 2023 software supply-chain attack: a phished former Ledger employee's npm key let attackers publish malicious versions of Ledger's widely used 'Connect Kit' library, injecting the Angel Drainer into many dApps. About $500K–$600K was drained in a few hours before a fix shipped.
This page was last updated on Jun 15, 2026. View revision history.
