Lazarus Group: Inside North Korea’s Notorious Hacking Organization Behind Billion-Dollar Cyber Heists

For more than a decade, the Lazarus Group has been regarded as one of the world's most sophisticated and dangerous cybercrime organizations. Security researchers and government agencies have linked the group to massive cyberattacks targeting banks, cryptocurrency exchanges, multinational companies, and government institutions.

Unlike ordinary cybercriminals driven solely by financial gain, Lazarus is widely believed to operate on behalf of the North Korean government, making it one of the most influential state-sponsored hacking groups in the world.  

What Is the Lazarus Group?

The Lazarus Group is an advanced persistent threat (APT) organization that cybersecurity experts believe has been active since at least 2009. The group gained global attention after a series of high-profile cyberattacks demonstrated both its technical capabilities and strategic planning.

According to multiple intelligence agencies, Lazarus has targeted:

  • Cryptocurrency exchanges
  • International banks
  • Government agencies
  • Defense contractors
  • Technology companies
  • Healthcare organizations

Its operations combine phishing, malware, software supply-chain attacks, social engineering, and custom-built hacking tools to infiltrate highly secure systems.  

DeepSeek Founder Liang Wenfeng Is Now the World's Richest AI Startup Founder With a $36 Billion Fortune

Major Cyberattacks Linked to Lazarus Group

Over the years, the group has been connected to numerous high-profile incidents, including:

Sony Pictures Hack (2014)

One of Lazarus Group's earliest internationally recognized attacks targeted Sony Pictures Entertainment. Sensitive corporate emails, unreleased films, and confidential employee information were leaked after the breach.

WannaCry Ransomware (2017)

The infamous WannaCry ransomware infected hundreds of thousands of computers across more than 150 countries, disrupting hospitals, businesses, and government organizations worldwide. Several governments later attributed the attack to Lazarus Group.  

Bangladesh Bank Heist

Hackers attempted to steal nearly $1 billion from Bangladesh Bank through the SWIFT banking network. Although most transactions were blocked, approximately $81 million was successfully stolen, making it one of history's largest banking cyber thefts.  

The Record-Breaking Bybit Hack in Dubai

One of the most significant cyberattacks ever attributed to Lazarus Group occurred in February 2025, when Dubai-based cryptocurrency exchange Bybit suffered what investigators describe as the largest cryptocurrency theft in history.

Attackers compromised the transaction-signing process during a routine transfer from an Ethereum cold wallet. Rather than exploiting Bybit's own infrastructure directly, investigators concluded that the hackers manipulated a third-party wallet platform used to authorize transactions. This allowed them to redirect approximately 400,000 ETH, valued at roughly $1.46 billion, to wallets under their control.  

The incident caused immediate concern throughout the cryptocurrency industry, triggering massive withdrawal requests from users and renewed debates over exchange security and cold-wallet protection.

Following investigations by blockchain security firms and the FBI, the attack was attributed to the North Korean-backed Lazarus Group. Bybit later confirmed that customer assets remained fully backed despite the loss and launched a bounty program to help recover the stolen funds.  

Why Does Lazarus Target Cryptocurrency?

Cybersecurity analysts believe cryptocurrency has become one of Lazarus Group's primary revenue sources because digital assets can be transferred globally within minutes and are considerably harder to trace than traditional banking transactions.

After major thefts, the group typically:

  • Splits stolen funds across hundreds of wallets
  • Uses cross-chain bridges
  • Utilizes cryptocurrency mixers
  • Moves assets through decentralized exchanges
  • Gradually converts assets into other cryptocurrencies

These techniques make recovery efforts extremely difficult for investigators.  

How Dangerous Is Lazarus Group?

Unlike conventional cybercriminal organizations, Lazarus possesses the resources and patience associated with a state-sponsored intelligence operation. Security experts note that the group often spends months researching targets before launching attacks, combining technical exploits with carefully crafted social engineering campaigns.

Its operations have evolved from espionage and sabotage into highly profitable financial crimes, particularly against cryptocurrency platforms, making Lazarus one of the most closely monitored cyber threat actors in the world. (arXiv)

Can Cryptocurrency Exchanges Stop Attacks Like This?

Modern exchanges continue investing heavily in cybersecurity through:

  • Multi-signature wallets
  • Hardware security modules
  • Real-time blockchain monitoring
  • Independent security audits
  • Multi-factor authentication
  • Behavioral threat detection

However, the Bybit incident demonstrated that even organizations with advanced security systems remain vulnerable when attackers successfully compromise trusted third-party infrastructure or exploit human decision-making rather than software vulnerabilities alone. 

 

Sources:
  • prnewswire.co.uk

Help us keep GotFort ad-free and accessible to everyone. Your contribution supports independent content, research, and publishing.

5.00 USD PayPal