Darknet

All Attacks Carried Out by the Lazarus Group: From Banks to Blockchain (2014–2026)

All Attacks Carried Out by the Lazarus Group: From Banks to Blockchain (2014–2026)

For years, the Lazarus Group has been one of the world's most dangerous and prolific cybercriminal groups. Linked to the North Korean regime, the group has targeted banks, technology companies, financial institutions, exchanges, and DeFi protocols. Its evolution is particularly noteworthy: moving from destructive attacks, such as those against Sony Pictures and the WannaCry ransomware, Lazarus progressively shifted toward direct theft of funds, initially via the traditional banking system and later by exploiting the cryptocurrency boom.
It is not merely a matter of phishing or technical vulnerabilities. Their most sophisticated operations have combined malware, social engineering, developer compromise, supply chain attacks, transaction manipulation, and prolonged periods of infiltration.

Considering the major attacks directly attributed to, or highly likely linked to, North Korean groups within the Lazarus ecosystem, the list includes at least:

• Bybit ($1.5B).
• Ronin Bridge ($625M).
• Bitget ($388M).
• DMM Bitcoin ($308M)
• KelpDAO ($292M) – unconfirmed.
• Drift ($285M) – unconfirmed.
• WazirX ($235M).
• Harmony Bridge ($100M).
• Atomic Wallet ($100M).
• Bangladesh Bank ($81M).
• Alphapo ($60M).
• CoinEx ($54M).
• Stake ($41M).
• CoinsPaid ($37.3M).

The simple sum of these figures exceeds $4.1 billion. However, a clarification is necessary: ​​not all these cases carry the same level of official attribution. For instance, the FBI has explicitly attributed the attacks on Ronin, Harmony, Atomic Wallet, Alphapo, CoinsPaid and Stake to North Korean operators associated with TraderTraitor/Lazarus. In the case of Bybit, however, the FBI officially attributed the theft of approximately $1.5 billion to North Korea, identifying the activity as "TraderTraitor".

 

THE ATTACK ON BYBIT
The heist targeting Bybit, which took place in February 2025, remains one of the most striking cases. Approximately $1.5 billion in digital assets was stolen during an operation that exploited a compromise in the environment used to manage transactions. The FBI subsequently attributed the operation to North Korea. The attack successfully manipulated the process by which transactions were displayed and authorized. Following the theft, the attackers immediately began moving and converting the assets across thousands of addresses and various blockchains, making it extremely difficult to freeze the funds. The FBI warned exchanges, bridges, blockchain analytics companies, and other crypto operators to block addresses linked to the laundering of the funds.

31cb06e98297d26f5ee250a8966f6e9b163c0494a1059a73cdacd2d4ea6337cf.jpg

 

RONIN BRIDGE EXPLOIT
In March 2022, the Lazarus Group targeted the Ronin Bridge, the infrastructure connecting the Axie Infinity ecosystem to the Ethereum network. Approximately $625 million was stolen—at the time, one of the largest thefts in cryptocurrency history. The operation demonstrated how lucrative it could be to attack not necessarily an exchange, but the infrastructure enabling asset transfers between blockchains. Historically, bridges have been the weak link in DeFi.

 

DMM BITCOIN EXCHANGE
In May 2024, the Japanese exchange DMM Bitcoin lost approximately 4,502.9 BTC, equivalent at the time to around $308 million. The FBI, together with the Department of Defense Cyber ​​Crime Center and the Japanese National Police Agency, attributed the attack to North Korean cyber actors linked to the "TraderTraitor" campaign. According to the official account, the operation began weeks earlier via social engineering: an attacker posed as a recruiter on LinkedIn and targeted an employee of Ginco, a Japanese company providing wallet infrastructure. This is a perfect example of how Lazarus does not necessarily need to attack the ultimate target directly; it can infiltrate a service provider and use that position as a gateway.


WAZIRX EXCHANGE
In July 2024, the Indian exchange WazirX was hit by a theft amounting to approximately $235 million. The incident involved a multi-signature (multisig) wallet managed jointly with the custodian Liminal. The attack was subsequently linked to Lazarus by various analysts and placed within the broader context of North Korean-linked thefts in 2024.

 

THE ATTACK ON LAYERZERO AND KELP DAO
In April 2026, KelpDAO lost approximately $292 million. LayerZero identified a North Korean actor linked to Lazarus/TraderTraitor as the likely culprit. The attack exploited a compromised RPC infrastructure used by the bridge's verification system; the attackers managed to feed false information to the system, making an illegitimate transaction appear valid. The theft was then completed by depositing this collateral on Aave and taking out a loan that was never repaid (some of these funds were frozen by the Arbitrum Layer 2 network to prevent them from moving to more decentralized chains).

87a66797e8638fe357111a65494617f8f815566ff8609b86bb0bb23cedc54fb6.jpg

 

DRIFT EXCHANGE
Just days earlier, on April 1, 2026, Drift Protocol, a decentralized perpetual futures exchange on Solana, was hit for approximately $285 million. This operation is particularly interesting because it was not a standard smart contract exploit. According to reconstructions, the attackers spent months building relationships with members of the Drift ecosystem, posing as a quantitative trading firm. The final phase involved Security Council member authorizations and the use of "durable nonce" transactions, which allowed the attackers to gain administrative control. Subsequently, a virtually worthless token was used as collateral to drain real assets. Some analyses have pointed to other North Korean clusters, making attribution to Lazarus uncertain.


NOT JUST CRYPTO
The story of Lazarus predates DeFi by a long time. In 2014, the group targeted Sony Pictures Entertainment in a destructive attack that resulted in the theft and release of massive amounts of data and paralyzed part of the company's infrastructure. According to the U.S. Department of Justice, the attack was linked to North Korea's retaliation against Sony over the film "The Interview". In February 2016, Lazarus demonstrated its ability to directly attack the international financial system. The attackers breached Bangladesh Bank's systems and used compromised credentials to send fraudulent orders via the SWIFT system, the network banks use to communicate payment instructions. The target amount was massive: nearly $1 billion. Ultimately, however, most of the transfers were blocked. Approximately $81 million did reach the intended recipients and was subsequently laundered. According to the DOJ, between 2015 and 2019, North Korean operatives attempted to steal a total of over $1.2 billion from banks in various countries through cyber intrusions and fraudulent SWIFT messages.

8fe9d91217e1bd1e3af2c3c03cbf9146f803ec39b541c4e392740df2f87facdf.jpg

In May 2017, the WannaCry malware spread globally. The ransomware encrypted files on infected computers and demanded payment in Bitcoin. The attack affected hundreds of thousands of computers and organizations across numerous countries, causing disruptions even to critical infrastructure. In 2018, the United States charged Park Jin Hyok, a member of the North Korean group identified by the DOJ as Lazarus with involvement in creating the malware used in the WannaCry operation.

 

ATTACK TECHNIQUES
Lazarus's most dangerous characteristic is its ability to combine different disciplines:

- Social engineering.
- Malware.
- Phishing.
- Supply-chain attacks.
- Compromise of developers.
- Transaction falsification.
- Attacks on cloud infrastructure.
- On-chain laundering.

The DMM Bitcoin case illustrates social engineering. KelpDAO demonstrates an attack on infrastructure. Drift highlights a prolonged operation involving infiltration and human manipulation. Bybit shows the sophistication involved in manipulating a signing process. And the Bangladesh Bank incident proves that this model existed long before the advent of DeFi. In many cases, attackers first establish access and only later monetize the operation.


THE THREE MEN WANTED BY THE FBI
The United States has publicly identified three members of the North Korean conspiracy associated with Lazarus. Park Jin Hyok is the most well-known of the three. He was indicted in the U.S. in 2018, and the FBI placed him on its wanted list. Charges include conspiracy, bank fraud, wire fraud, and computer intrusions. According to the DOJ, Park was linked to attacks on Sony Pictures, Bangladesh Bank and the WannaCry incident. He has been a wanted man since 2018. Jon Chang Hyok allegedly participated in the broader North Korean conspiracy and in the development and distribution of malware targeting exchanges and other companies. He has been wanted since 2020. Kim Il, also indicted in 2020, is accused of activities related to malware development and distribution, cyber-heists against financial institutions, and the Marine Chain project. According to U.S. prosecutors, Marine Chain was an ICO project used as part of North Korea's efforts to secure funding and evade international sanctions. Kim Il has also been a wanted man since 2020.

653b0a6278da004fe444ed2693e95a7ab09bc3912d281ab61b6b35f3d22b4f4d.jpg

The DOJ has identified the North Korean military units involved by various names used within the cybersecurity community, including Lazarus Group and APT38. None of the three has been arrested, so they remain operational.

 

Article always updated with all the possibilities of on-chain farming (airdrop): Some Sites To Earn Crypto Bonus (Old & New)  

How do you rate this article?

9


☑️0🆇D̺͈͙͕̿ͧ̑ͣ🅰🆅🅸🅳eͤ
☑️0🆇D̺͈͙͕̿ͧ̑ͣ🅰🆅🅸🅳eͤ Verified Member

I love Bitcoin since 2012. I also love NFT. #BTC #ETH #MLBSorare


Darknet
Darknet

The topics will be 🅒🅡🅨🅟🅣🅞, of course. BTC and Degen crypto since 2012.⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀

Publish0x Publish0x

Reward the author with $0.01 in crypto, and earn yourself as you read!

20% to author / 80% to me.
Rewards are FREE. Publish0x pays them, not you.

Page not displaying correctly?