The Lazarus Group: A Persistent Force in Cybercrime
Lazarus Group is a persistent force in the world of cybercrime, typically associated with some of the largest cryptocurrency heists.
Coinbase, Cointelegraph
According to Cointelegraph, the North Korean-backed hacking group has stolen billions of dollars by targeting exchanges, deceiving developers, and bypassing even the most advanced security systems.
Recent Attack on Bybit
On February 21, 2025, the group carried out its biggest theft yet, taking $1.4 billion from the cryptocurrency exchange Bybit. Crypto investigator ZachXBT linked the attack to an $85 million hack on Phemex and additional breaches at BingX and Poloniex, further strengthening the case against Lazarus.
The Structure Behind Lazarus Group
The US Treasury identifies Lazarus as being under North Korea’s Reconnaissance General Bureau (RGB), the country’s intelligence agency. The FBI has identified three suspected North Korean hackers associated with the group, also known as APT38.
The Bybit Attack
Just days before the Bybit hack, North Korea’s leadership reaffirmed plans to expand its nuclear arsenal, while the US, South Korea, and Japan issued a joint statement urging denuclearization. Three days later, Lazarus executed another major breach.
Lazarus’ Expanding Cyber Operations
North Korean hackers are accelerating their attacks. In 2024 alone, they stole $1.34 billion across 47 breaches, more than double the $660.5 million stolen in 2023, according to Chainalysis. The firm reports that private key compromises accounted for nearly 44% of all crypto hacks that year, a method Lazarus has used in heists like the $305 million DMM Bitcoin breach and the $600-million Ronin hack.
Conclusion
Lazarus Group is a persistent force in the world of cybercrime, with a history of stealing billions of dollars from cryptocurrency exchanges and deceiving developers. Despite increasing scrutiny from law enforcement and cybersecurity organizations, the group continues to adapt and evolve its tactics, posing a growing threat to national security.
Frequently Asked Questions
What is the Lazarus Group? Lazarus Group is a North Korean-backed hacking group responsible for some of the largest cryptocurrency heists.
What is the purpose of the group? The group’s primary goal is to steal cryptocurrency and fund North Korea’s weapons program.
How does the group operate? Lazarus Group uses a variety of tactics, including hacking, phishing, and malware distribution to carry out its attacks.
What is the impact of the group’s activities? The group’s activities have resulted in the theft of billions of dollars and have posed a significant threat to national security.
What is being done to combat the group’s activities? Law enforcement and cybersecurity organizations are working to disrupt the group’s activities through federal indictments and multi-agency crackdowns.
