Lazarus Group
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Contagious Interview is a threat actor identified by that alias in open‑source reporting. The actor is known to operate from North Korea, as indicated by geographic attribution in threat intelligence. Public sources describe the actor as financially motivated, focusing on the acquisition of virtual currency. Activity linked to the alias has been observed targeting digital asset platforms and related financial infrastructure. The actor’s tradecraft includes the exploitation of trusted relationships with third‑party service providers.
On February 1 2025, the actor carried out a theft of approximately $1.5 billion in Ethereum from the Bybit cryptocurrency exchange. The intrusion began with a supply‑chain compromise of a trusted third‑party developer that had access to Bybit’s development environment. By exploiting this trusted relationship, the attacker gained initial entry into the exchange’s internal networks. Once inside, the actor executed a series of native token swaps and cross‑chain transactions to move the stolen Ether across multiple blockchains. These actions were intended to obscure the provenance of the funds and hinder forensic tracing. After the transfer, the stolen assets were broken down into smaller denominations and routed through numerous liquidity services. Rather than depositing the funds into centralized exchanges, the actor used decentralized money‑laundering networks to further conceal the trail. The overall operation illustrates a pattern of using supply‑chain access, cross‑chain obfuscation, and decentralized laundering to achieve financial gain.
The February 2025 Bybit theft was publicly attributed to the Lazarus threat group, which is widely regarded as a North Korean state‑sponsored operation. While the alias Contagious Interview has not been explicitly linked to Lazarus in open sources, the incident demonstrates the tactical overlap seen in North Korean‑linked cyber activity. The attack underscores the continued use of trusted‑relationship exploitation as an initial access vector by these actors. It also highlights a preference for cross‑chain movement and decentralized laundering techniques to evade detection. Collectively, these behaviors point to a financially driven, North Korea‑associated threat capability that persists in targeting cryptocurrency sectors.
Incidents
Attributed incidents are available to members.
1 incident