Lazarus Group
Attribution profile
- Type
- Undetermined
- Location
- North Korea
- Known incidents
- 1 incident
- Sources
- 0 sources
- First seen
- 2025-01-01
- Last seen
- 2025-01-01
- Updated
- 2026-09-10 19:40
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is known publicly as North Korean state-sponsored hackers, an alias that reflects its attribution to the government of North Korea. Operating from North Korea, the group is characterized as a state-sponsored entity rather than a purely criminal collective. Its activities have been linked to the country's sanctioned weapons programs, with stolen funds reportedly directed toward those programs. This establishes a clear financial motive tied to state objectives. The actor's affiliation with the North Korean state is the basis for most public attributions.
The actor primarily targets the cryptocurrency sector, focusing on exchanges, decentralized exchanges and liquidity protocols. These targets are chosen because they hold large volumes of digital assets that can be transferred quickly and anonymously. The group's campaigns are not limited to a single geographic region; instead, they pursue vulnerable platforms wherever they are accessible online. Over multiple years, the actor has been responsible for a series of high-value thefts that together amount to several billion dollars. This pattern demonstrates a sustained focus on cryptocurrency infrastructure as a means of generating revenue.
A representative example occurred on 2025-01-01 when a major cryptocurrency exchange lost approximately $1.4 billion in a single attack attributed to the actor. This theft was part of a broader wave in 2025 that saw roughly $2.7 billion removed from various digital asset platforms. Other notable incidents include a breach of a decentralized exchange that resulted in losses exceeding $223 million and an exploit of a liquidity protocol that yielded over $128 million. These cases illustrate the actor's capability to execute large-scale heists across different types of crypto services. Collectively, such operations underscore the actor's role as a prolific offender in the realm of state-linked cyber theft.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 0 sources.