CSIDB logo
Threat actor

CryptoCore

Attribution profile

Type
Undetermined
Location
North Korea
Known incidents
1 incident
First seen
2025-02-01
Last seen
2025-02-01
Updated
2026-09-02 17:15
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

CryptoCore is a threat actor alias that has been observed in open‑source reporting and is publicly associated with North Korean cyber operations. The alias has been linked to the Lazarus group, a North Korean state‑sponsored entity known for conducting cyber activities that generate revenue for the regime. Observations place the actor’s operational base within North Korea, indicating a direct state nexus rather than a purely criminal enterprise. Threat intelligence sources consistently list CryptoCore alongside other North Korean designations when discussing financially motivated cyber campaigns.

In February 2025 the actor carried out a supply‑chain compromise against a third‑party software developer that maintained a trusted integration with the Bybit cryptocurrency exchange. By exploiting the developer’s legitimate access, CryptoCore gained a foothold inside Bybit’s internal network without triggering conventional perimeter alerts. Once inside, the actor executed a rapid sequence of native token swaps and cross‑chain transfers that moved approximately 1.5 billion dollars worth of Ethereum across several blockchain networks. The series of swaps was deliberately structured to fragment the transaction trail, making it difficult for blockchain analysts to follow the funds to a single destination. Public attribution connected the incident to the Lazarus group, and analysts described it as one of the largest single‑event cryptocurrency thefts ever disclosed. The theft contributed to a year in which North Korean cyber groups set new records for the volume of digital assets stolen.

The actor’s typical initial access method involves compromising trusted software supply chains, using legitimate developer credentials to bypass firewalls and intrusion‑detection systems. After establishing presence, CryptoCore relies on built‑in blockchain swap functions and decentralized cross‑chain bridges to disperse stolen assets through numerous liquidity pools and decentralized exchanges. Rather than consolidating the proceeds on a centralized exchange where they could be more easily frozen, the actor routes the funds through a chain of mixing services, tumblers, and peer‑to‑peer channels. This laundering strategy is intended to obscure the origin of the assets and impede any attempts at seizure or recovery by law‑enforcement or private‑sector investigators. Overall, the observed behavior demonstrates a financially motivated operation that emphasizes stealth and concealment over disruption, espionage, or destructive effects.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB