Lazarus and North Korea’s crypto theft network has now been tied to nearly $7.8 billion

Lazarus and North Korea’s crypto theft network has now been tied to nearly $7.8 billion

N
News Editor
2026-09-30 01:10:57
The September 2026 Bitget hack has pushed North Korea-linked cyber activity back to the center of the crypto security debate. Bitget first disclosed losses of about $351.6 million, then revised the confirmed amount of transferred assets to $387.5 million. TRM Labs said parts of the laundering trail overlapped with earlier North Korea-linked attacks including Bybit and AFX Bridge, while Elliptic assessed a North Korea connection as “highly likely.” That latest case sits inside a much longer record. Over the past decade, investigators, law enforcement agencies, and security firms have used names such as Lazarus Group, BlueNoroff, APT38, TraderTraitor, Citrine Sleet, Andariel, and Famous Chollima to describe overlapping North Korean cyber units tied to the Reconnaissance General Bureau, or RGB. The naming varies by firm, but the operational pattern is consistent: financial theft, crypto-focused intrusions, malware campaigns, supply-chain compromises, espionage, and covert workforce infiltration. Publicly attributed crypto thefts linked by governments and law enforcement to North Korean actors exceed $3.1 billion based on major named cases alone, including Ronin Bridge, Harmony Horizon Bridge, Atomic Wallet, Stake, DMM Bitcoin, and Bybit. Broader blockchain-tracing estimates are much higher. Chainalysis put the cumulative total at no less than $6.75 billion by the end of 2025, and with the still-unresolved Bitget case added to the picture, the running total cited in the source article approaches $7.8 billion as of September 2026.

On Sept. 24, 2026, Bitget disclosed a hack after abnormal transfers were detected from some of its hot and warm wallets. The exchange initially put the loss at about $351.6 million, then revised the confirmed amount of transferred assets to $387.5 million.

Lazarus and North Korea’s crypto theft network has now been tied to nearly $7.8 billion 2

TRM Labs said parts of the laundering trail in the Bitget case overlapped with earlier North Korea-linked attacks, including Bybit and AFX Bridge. Elliptic separately said a connection to North Korea-linked hackers was “highly likely.” As investigators traced more on-chain flows, attention again turned to Lazarus Group.

From Ronin Bridge and Harmony to Atomic Wallet, Stake, WazirX, DMM Bitcoin, and the 2025 Bybit theft, North Korea-linked operators have become one of the biggest security threats in the global crypto market. If the still-unresolved Bitget case is included as a highly suspected North Korea-linked incident, the cumulative amount approaches $7.8 billion.

In crypto, “Lazarus” is often treated as the name of a single hacking group. The source article argues that the label is better understood as shorthand for a broader North Korean state cyber apparatus. Within that system, some units focus on government, military, and strategic intelligence targets, some on banks and financial institutions, and others on exchanges, wallets, blockchain companies, and crypto workers.

That is why so many names appear across public reporting: BlueNoroff, APT38, TraderTraitor, Jade Sleet, Sapphire Sleet, Citrine Sleet, AppleJeus, and Famous Chollima, among others. The names come from different tracking systems used by different security firms, and the overlap in personnel, tools, and infrastructure makes a clean org chart difficult.

How Lazarus fits into North Korea’s cyber structure

To understand Lazarus, the article starts with its place inside North Korea’s cyber system.

In 2019, the U.S. Treasury sanctioned three North Korean cyber organizations and named Lazarus Group, BlueNoroff, and Andariel. Treasury said all three were controlled by North Korea’s Reconnaissance General Bureau, or RGB, one of the country’s main intelligence bodies and a central hub for overseas intelligence and cyber operations.

That provides the basic frame: RGB oversees state intelligence and cyber activity, while multiple subordinate cyber units carry out different missions. Lazarus is one of the oldest and most widely recognized labels attached to that structure.

The names themselves largely come from years of tracking by the global security industry. As campaigns evolved, Microsoft, Mandiant, CrowdStrike, and others split activity into smaller clusters based on malware families, server infrastructure, target sectors, and attack methods.

As a result, the same campaign line can carry several names at once. Microsoft maps Diamond Sleet to Lazarus, ZINC, and LABYRINTH CHOLLIMA. It links Sapphire Sleet to BlueNoroff, CryptoCore, UNC1069, and STARDUST CHOLLIMA. Mandiant uses a different system: much of what was once described as traditional Lazarus activity falls under TEMP.Hermit, while financial operations involve APT38, and crypto-focused activity includes CryptoCore (UNC1069), TraderTraitor (UNC4899), and UNC4736, which is tied to AppleJeus.

The naming confusion is not accidental. North Korean cyber units have long shared personnel, code, malware, and infrastructure. Around 2020, some operators were believed to be using common servers and tooling, and task groups may have been reorganized. After APT38 went quiet for a period, some of its personnel were thought to have moved into newer financial and crypto attack units.

That means one incident can appear under different group names in different reports, and two apparently separate groups may still belong to closely related personnel and operational systems.

The source article groups the broader activity into several mission sets: traditional cyber operations, financial theft, large crypto thefts, crypto malware and supply-chain attacks, military intelligence, and the fast-growing remote IT worker infiltration model. In practice, many of these are still folded into the Lazarus label.

The main operational lines inside the Lazarus ecosystem

The article breaks the activity into six relatively clear lines:

  • Diamond Sleet, focused on broad cyber operations.
  • BlueNoroff, long focused on financial institutions and crypto.
  • TraderTraitor, aimed at exchanges, custodians, and large crypto targets.
  • Citrine Sleet, known for malware, supply-chain compromises, and crypto-targeted attacks.
  • Andariel, centered on military, defense, and strategic intelligence.
  • Famous Chollima, which uses false identities to enter tech and crypto firms from the inside.

Of those, BlueNoroff, TraderTraitor, Citrine Sleet, and Famous Chollima are the lines most closely tied to the crypto market.

1. Diamond Sleet

Diamond Sleet is the closest match to what many people mean when they say Lazarus Group. It has been active since at least around 2013 and has targeted governments, defense, military contractors, telecoms, financial institutions, and technology companies. Its core missions include strategic intelligence theft, network intrusion, and destructive operations, though it also has financial attack capability.

The group has long used spear-phishing, malware, supply-chain attacks, and social engineering against internal staff. It has also used fake recruiters and LinkedIn profiles to lure targets into opening malicious files or programs under the pretense of job opportunities.

In the article’s framing, Diamond Sleet is the oldest and broadest operational line in the system.

2. BlueNoroff

In the 2019 sanctions documents, the U.S. Treasury described BlueNoroff as an important financial attack arm within the Lazarus system. Microsoft refers to it as Sapphire Sleet.

BlueNoroff was already conducting large-scale theft campaigns against banks, SWIFT systems, and other financial institutions around 2014. By 2018, the amount it had attempted to steal from financial institutions worldwide had exceeded $1.1 billion. The Bangladesh central bank case remains one of the best-known examples from that period.

As the crypto market expanded, BlueNoroff shifted from traditional finance toward exchanges, blockchain companies, venture capital firms, and crypto workers. Its main targets now include crypto, VC, blockchain, and other high-value financial institutions. The goal is theft of crypto assets and related technology, and social engineering is central to the playbook.

Operators often pose as recruiters, investors, peers, or business partners on LinkedIn and Telegram. They then use fake interviews, project collaboration, Zoom meetings, or software updates to get victims to run malicious code.

Mandiant described one UNC1069 case this year in which attackers first took over a contact’s Telegram account, then invited the target to a fake Zoom meeting and allegedly used an AI-generated video to impersonate the CEO of another crypto company. They then cited an “audio issue” and persuaded the victim to run a supposed fix command, which installed malware on the device.

Lazarus and North Korea’s crypto theft network has now been tied to nearly $7.8 billion 3

In 2026, Microsoft attributed npm supply-chain attacks involving Axios and Mastra to BlueNoroff. The Mastra incident affected more than 140 npm packages. If developers or CI/CD systems installed the tainted versions, the malicious code could run automatically and steal credentials, tokens, and access to development environments.

BlueNoroff started with banks and SWIFT. It later made crypto a core target, while its methods expanded from phishing and backend intrusion to fake recruiting, fake meetings, AI-assisted social engineering, and supply-chain poisoning.

3. TraderTraitor

TraderTraitor is one of the main crypto attack forces in North Korea’s cyber structure. The FBI and Mandiant commonly associate it with names including UNC4899, Jade Sleet, and Slow Pisces. Mandiant says UNC4899 is tightly focused on the crypto industry, especially blockchain companies and related financial infrastructure, and places it within the RGB system.

The group’s defining trait is target selection. It looks for people who can reach trading systems, wallet systems, and internal privileges. Typical targets include developers, DevOps staff, system administrators, wallet managers, and employees with access to signing systems and fund management infrastructure.

A common method is to pose as recruiters on LinkedIn and use technical interviews, coding tests, or GitHub projects to trick targets into running malicious code. From there, the attackers steal accounts, session cookies, and internal permissions, then move deeper into wallet or trading systems.

The 2024 DMM Bitcoin theft is a textbook example. TraderTraitor posed as a recruiter on LinkedIn, contacted an employee at Japanese enterprise wallet company Ginco, and sent a malicious Python script disguised as a recruiting test. The attackers then used a stolen session cookie to impersonate that employee, entered Ginco’s internal communications system, and ultimately manipulated a legitimate DMM Bitcoin transaction request.

The theft moved 4,502.9 BTC, worth about $308 million at the time. The FBI and Japan’s National Police Agency later formally attributed the incident to TraderTraitor.

On Feb. 21, 2025, Bybit lost about $1.5 billion in crypto assets, one of the largest single thefts in the history of the industry. Five days later, the FBI formally said North Korea was responsible and explicitly labeled the activity TraderTraitor.

The FBI has also tied TraderTraitor to several other major crypto cases. In 2023, it linked the operation to roughly $100 million stolen from Atomic Wallet, about $60 million from Alphapo, and about $37 million from CoinsPaid. The article also says the group was involved in major incidents including Ronin Bridge and Harmony Horizon Bridge.

TraderTraitor’s targeting is narrow and deliberate. It keeps its attention on crypto executives, internal security teams, and critical infrastructure, and has also used software supply chains such as JumpCloud to reach downstream corporate networks.

As the article presents it, TraderTraitor is the clearest example of a North Korean unit built for large-value crypto theft. It does not spend much effort on ordinary retail wallets. It goes after exchanges, custodians, wallet systems, and blockchain infrastructure where a single compromise can expose tens of millions, hundreds of millions, or even billions of dollars.

4. Citrine Sleet

Citrine Sleet is another long-running North Korean line focused on crypto. Other names attached to it include AppleJeus, UNC4736, Labyrinth Chollima, and Hidden Cobra. It is believed to target financial institutions, crypto companies, and individuals who manage crypto assets.

Its signature capability is the development and distribution of malware built around crypto use cases. As early as 2018, security researchers found North Korean operators distributing tampered crypto trading software through websites that looked legitimate. Once installed, the malware could take control of the device, steal credentials, and create a path to crypto theft.

The FBI, CISA, and the U.S. Treasury later grouped that malware family under the AppleJeus name. The U.S. government said that in just one year, the related attacks had reached crypto companies and individuals in more than 30 countries.

The attack design closely matches the daily workflow of crypto professionals. Operators build polished trading platform websites and distribute wallet software, trading tools, or investment applications that appear normal. Some of the software even works as advertised, while the malicious code is hidden in update mechanisms or background components.

Later, the model expanded into more complex supply-chain operations. In 2023, Mandiant tracked part of the 3CX software supply-chain attack as UNC4736 and said it was closely related to AppleJeus. The chain began with Trading Technologies’ X_TRADER software, which had already been implanted with malicious code, and then spread through 3CX software updates to downstream companies. The article describes this as a supply-chain attack on top of another supply-chain attack.

Citrine Sleet also has strong exploit capability. In 2024, Microsoft said the group used the Chromium browser zero-day CVE-2024-7971 in attacks on the crypto sector. When a target visited an attacker-controlled site, the flaw could be used for remote code execution, followed by a browser sandbox escape and deployment of the FudModule rootkit.

FudModule is a technically advanced rootkit that can interfere directly with the Windows kernel and evade security detection. Both Diamond Sleet and Citrine Sleet have used it, which points again to tool sharing across North Korean clusters.

Fake trading platforms, fake wallets, software supply chains, browser exploits, and malware tailored to crypto workflows define Citrine Sleet’s role in the broader system.

5. Andariel

Andariel is another long-active force in North Korea’s cyber structure. It is also known as Onyx Sleet and APT45.

The U.S. Treasury sanctioned Andariel alongside Lazarus and BlueNoroff in 2019 and said it was controlled by the RGB. Its core mission set centers on military, defense, energy, nuclear industry, government agencies, and critical infrastructure.

Mandiant casework indicates that Andariel has been active since at least 2009, conducting cyber espionage aligned with North Korea’s strategic needs. Its early targets were mainly government and defense organizations, later expanding to nuclear industry, healthcare, finance, and other critical sectors.

Compared with the crypto-focused lines above, Andariel is more intelligence-driven. In one 2023 case disclosed by South Korean authorities, the group stole more than 1.2 TB of data from a South Korean defense contractor. Microsoft places malware families including TigerRAT, SmallTiger, LightHand, and ValidAlpha inside the Andariel toolset.

Lazarus and North Korea’s crypto theft network has now been tied to nearly $7.8 billion 4

Andariel later expanded into profit-driven operations and may have participated in ransomware development and deployment. The article says it has infrastructure, tooling, and personnel links to another North Korean ransomware group, Storm-0530.

In that sense, Andariel looks more like a strategic arm of the North Korean cyber system, focused on military technology, defense intelligence, and critical infrastructure penetration while also generating funds through ransomware and financial crime.

6. Famous Chollima

Famous Chollima is CrowdStrike’s name for North Korea’s remote IT worker activity.

These operators use false identities, fabricated resumes, VPNs, remote-control tools, and laptop farms to pose as local job seekers in the U.S. and Europe and apply for remote technical roles, including software development and blockchain development jobs. Once inside a company, they can write code, attend meetings, and collect salaries like ordinary employees. Some work for multiple companies at the same time.

Cases disclosed by the U.S. Justice Department show that wages were often paid in crypto assets such as USDC and USDT and ultimately flowed to North Korea.

CrowdStrike said in 2025 that Famous Chollima had successfully infiltrated more than 320 companies over the prior 12 months, up about 220% year over year. The operators were also using generative AI to build resumes and strengthen false identities, and in some cases trying real-time face-swapping tools during video interviews.

Crypto is one of the important target sectors. A developer who enters a crypto company can legitimately access GitHub, cloud servers, CI/CD systems, internal communications, and parts of wallet infrastructure. Beyond salary income, those workers may retain internal access that can later support financial crime.

The crypto theft record: how much has been stolen

The article traces North Korea-linked crypto theft back to at least 2017.

According to disclosures from the U.S. Justice Department, hackers tied to North Korea’s RGB have been attacking crypto companies and virtual asset service providers worldwide since 2017. The scale grew from tens of millions of dollars in early cases to hundreds of millions, then reached $1.5 billion in a single incident with Bybit in 2025.

To avoid mixing suspected attributions from private firms with formally confirmed cases, the article lists incidents that governments or law enforcement agencies, including the U.S. Justice Department, the FBI, and police in Japan and South Korea, have publicly attributed to North Korean hackers, Lazarus, or related clusters.

2017: Slovenian crypto company

In an indictment against three North Korean RGB hackers, the U.S. Justice Department said that in December 2017, North Korean hackers stole about $75 million in crypto assets from a Slovenian crypto company.

2018: Indonesian crypto company

The same court filing said that in September 2018, North Korean hackers stole about $24.9 million from an Indonesian crypto company.

2018: South Korean crypto exchange

The U.S. Justice Department later disclosed that North Korean hackers breached a South Korean crypto exchange in 2018 and stole nearly $250 million in virtual assets. The funds were then laundered through hundreds of transactions and Chinese OTC networks. The exchange was not named in the U.S. court documents cited by the article.

2019: Upbit

In November 2019, 342,000 ETH was stolen from a hot wallet at South Korean exchange Upbit, worth about $41.5 million at the time.

After years of investigation, South Korea’s National Office of Investigation formally said in 2024 that the attack had been carried out jointly by Lazarus and Andariel under the RGB. The article notes that this was the first formal confirmation by South Korean investigators that North Korea had participated in a crypto asset theft targeting a South Korean exchange.

2020: New York financial services company

In August 2020, North Korean hackers used malware called CryptoNeuro Trader, disguised as a crypto trading tool, to enter a New York financial services company and steal about $11.8 million in crypto assets. The case was later included in the U.S. Justice Department’s formal indictment of three North Korean RGB hackers.

2022: Ronin Bridge

In March 2022, Ronin Bridge, the bridge behind Axie Infinity, was attacked and about $620 million in ETH and USDC was stolen.

In April that year, the FBI formally said Lazarus Group and APT38 were responsible. At the time, it was one of the largest crypto hacks on record.

2022: Harmony Horizon Bridge

Months later, Harmony Horizon Bridge was hit for about $100 million in crypto assets. In January 2023, the FBI formally said Lazarus Group was behind that attack as well.

North Korean hackers later used privacy protocol RAILGUN to launder more than $60 million in ETH from the theft and converted part of the funds into BTC.

2023: Atomic Wallet

In June 2023, Atomic Wallet suffered a large-scale attack in which about $100 million in crypto assets was stolen. The FBI later said the funds were tied to the North Korean TraderTraitor operation and linked the activity to Lazarus Group and APT38.

2023: Alphapo

That same year, payment service provider Alphapo was attacked. The FBI attributed about $60 million in stolen crypto assets to TraderTraitor.

Lazarus and North Korea’s crypto theft network has now been tied to nearly $7.8 billion 5

2023: CoinsPaid

CoinsPaid also lost about $37 million in the same wave. The FBI grouped the case with Atomic Wallet and Alphapo as TraderTraitor-linked crypto thefts.

2023: Stake

In September 2023, Stake lost about $41 million across Ethereum, BNB Chain, Polygon, and other networks. The FBI later said its investigation confirmed Lazarus Group was responsible.

2024: DMM Bitcoin

In May 2024, Japan’s DMM Bitcoin lost 4,502.9 BTC, worth about $308 million at the time. After a joint investigation by Japan’s National Police Agency, the FBI, and the U.S. Defense Department’s Cyber Crime Center, the case was formally attributed to North Korea’s TraderTraitor.

2025: Bybit

In February 2025, Bybit lost about $1.5 billion in crypto assets, one of the largest single thefts in crypto history. Five days after the attack, the FBI formally said North Korea was responsible and explicitly classified the activity as TraderTraitor.

If only publicly attributed major cases with confirmed loss figures are counted, the article says Lazarus and related North Korean groups have caused more than $3.1 billion in crypto losses.

Broader blockchain-tracing estimates are much higher. Chainalysis said that by the end of 2025, the lower-bound cumulative total stolen by North Korea-linked hackers had reached $6.75 billion, including about $2.02 billion in 2025 alone.

As of mid-September 2026, TRM Labs had attributed about $690 million in crypto theft to North Korea-linked hackers with medium-to-high confidence, including major incidents involving Drift Protocol and KelpDAO.

The Bitget case came after that. The confirmed amount transferred stands at about $387.5 million. Elliptic assessed the North Korea connection as “highly likely,” and TRM Labs found clear overlap between its laundering path and earlier TraderTraitor cases such as Bybit, though final attribution has not been completed.

Using the public figures cited in the source article, the cumulative amount stolen from the crypto market by North Korea-linked hackers is now close to $7.8 billion as of September 2026.

Why crypto became such an attractive target

The article ties crypto’s appeal to the structure of the market itself. Large exchanges, custodians, and protocols often control hundreds of millions or even billions of dollars in assets, so a single successful intrusion can produce an enormous payout.

Crypto assets also move globally around the clock. Once stolen, they can be converted quickly through DEXs, cross-chain protocols, and swap services, creating many routes for laundering.

How stolen funds are typically moved

The usual pattern is fast fragmentation, asset conversion, and cross-chain movement.

Attackers first split large balances across many fresh addresses. They then prioritize stablecoins such as USDT and USDC, along with other non-native assets that may be frozen, and convert them into native assets such as ETH, BNB, and BTC. From there, the funds move across chains. After several rounds of transfers and conversions, some of the money enters mixers, OTC channels, and underground financial networks, making the link between the stolen assets and the final holdings harder to trace.

The Bitget case offers a recent example. According to TRM Labs, the attackers quickly dispersed ETH and XRP into a batch of newly created wallets, with several addresses holding about 10,000 ETH or 20 million XRP each.

At the same time, some assets on BNB Chain and Ethereum were converted into BTC through THORChain and then split across multiple Bitcoin addresses. Some TRX on TRON was first swapped into USDT through SunSwap, then bridged to Ethereum and routed into the same THORChain path. Smaller amounts also moved through Across, Chainflip, and FixedFloat.

Stablecoins and other non-native assets stolen from Bitget were rapidly converted into native assets on their respective chains, and assets on Arbitrum were quickly bridged to Ethereum.

Earlier cases showed similar logic. After the 2022 Ronin Bridge theft, Lazarus moved stolen ETH through a large number of intermediary addresses, then sent batches into mixers such as Tornado Cash. Some ETH was later converted into BTC and processed through additional mixing and crypto-to-fiat channels. Chainalysis said the Ronin laundering process alone used more than 12,000 addresses. After Tornado Cash was sanctioned, Lazarus made greater use of cross-chain bridges and DeFi services for chain hopping.

After the roughly $1.5 billion Bybit theft in 2025, the pace was even faster. TRM Labs said that within 48 hours of the attack, at least $160 million had already entered later-stage laundering. By Feb. 26, the cumulative amount moved had exceeded $400 million. By March 3, the originally stolen ETH had largely been transferred into new addresses, with most of it converted into BTC through services including THORChain and then dispersed across new Bitcoin addresses. Some funds also entered anonymous exchange services such as eXch, creating repeated conversion paths between ETH and BTC.

The article argues that this pattern — reducing freeze risk first, then splitting funds, moving across chains, and gradually shifting into BTC — closely matches laundering behavior seen in earlier North Korea-linked crypto attacks. That is one reason the Bitget case has again been pointed toward the Lazarus ecosystem.

The attack surface has widened

From 2017 to now, Lazarus-linked activity has stretched across nearly a decade. The methods have moved well beyond direct attacks on banks, exchanges, and bridges. Fake recruiting, supply-chain compromise, remote IT worker infiltration, AI-assisted social engineering, and abuse of internal corporate access are now part of the same threat picture.

The target set has widened too. The risk no longer sits only in exchange hot wallets or protocol contracts. It now reaches into personnel, development environments, and fund management systems inside crypto companies.

As more assets move on-chain and exchanges, custodians, wallets, and protocols continue to manage larger pools of capital, any point with access to core systems and fund permissions can become an entry point. Based on the public figures cited in the article, the nearly $7.8 billion total may still be only part of the full picture.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.