#LazarusGroup
Bitget waved goodbye to $351.6 million after an intrusion into its hot wallets. At least their user protection fund gets some exercise today.

#CryptoHeist #LazarusGroup
September 25, 2026 at 7:04 AM
#FBI has confirmed that #NorthKorean hackers stole $1.5 billion from cryptocurrency exchange #Bybit on Friday in the largest crypto heist recorded until now.
#LazarusGroup #APT38 #CyberCrime www.bleepingcomputer.com/news/securit...
FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist
FBI has confirmed that North Korean hackers stole $1.5 billion from cryptocurrency exchange Bybit on Friday in the largest crypto heist recorded until now.
www.bleepingcomputer.com
February 27, 2025 at 8:11 AM
The Lazarus Group has been identified as a highly sophisticated, state-sponsored cyber threat group, posing significant risks in the digital landscape. #CyberSecurity #LazarusGroup www.cyfirma.com/research/apt...
APT PROFILE – LAZARUS GROUP - CYFIRMA
The Lazarus Group is a highly sophisticated, state-sponsored cyber threat group attributed to the North Korean government. They are also...
www.cyfirma.com
August 13, 2025 at 5:13 AM
#BitMEX uncovered security vulnerabilities in the operations of the North Korea-linked #LazarusGroup, including the leak of a real IP address & the #Supabase db. The investigation indicates the group is divided into sub-teams with varying capabilities.
#Cybersecurity #LazarusGroup #Crypto #DeFi
May 31, 2025 at 10:14 PM
Forensic investigators have found that North Korean Lazarus hackers stole $1.5 billion from #Bybit after hacking a developer's device at the multisig wallet platform Safe{Wallet}. #hacking #CyberCrime
#LazarusGroup #NorthKorean www.bleepingcomputer.com/news/securit...
Lazarus hacked Bybit via breached Safe{Wallet} developer machine
​Forensic investigators have found that North Korean Lazarus hackers stole $1.5 billion from Bybit after hacking a developer's device at the multisig wallet platform Safe{Wallet}.
www.bleepingcomputer.com
February 26, 2025 at 9:50 PM
"incredible visualization of all the regions whose economies were transformed by crypto"
https://x.com/divine_economy/status/1842191514874646844

#northkorea #dprk #lazarusgroup #crypto #uspol #eupol
March 10, 2025 at 10:41 PM
North Korean hackers escalate global crypto theft to $2.02B in 2025, accounting for 76% of all stolen funds. #CyberSecurity #Cryptocurrency #NorthKorea #LazarusGroup #CryptoTheft Link: thedailytechfeed.com/north-korean...
December 19, 2025 at 4:28 PM
🚨 Alert: North Korea’s Lazarus Group is at it again! They hid backdoor in fake npm packages, stealing credentials and crypto.

hackread.com/lazarus-grou...

#CyberSecurity #LazarusGroup #npm #NorthKorea
Lazarus Group Hid Backdoor in Fake npm Packages in Latest Attack
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
March 12, 2025 at 12:21 AM
A deep dive into the Lazarus subgroup reveals their tactics of hijacking cloud platforms, poisoning supply chains, and stealing billions in digital assets. #CyberSecurity #LazarusGroup www.wiz.io/blog/north-k...
TraderTraitor: Deep Dive | Wiz Blog
Inside the Lazarus subgroup that’s hijacking cloud platforms, poisoning supply chains, and stealing billions in digital assets
www.wiz.io
July 28, 2025 at 3:49 PM
North Korea’s #LazarusGroup just pulled off a bold new hack.

They posed as coworkers on Telegram, set up fake Calendly sites—and cycled through three custom RATs to compromise a DeFi employee’s system.

The scariest part? One tool may have exploited a Chrome zero-day.
#northkorea #ZeroDayAttacks
Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE
Lazarus Group used PondRAT, ThemeForestRAT, and RemotePE in a 2024 DeFi attack, likely via Chrome zero-day.
thehackernews.com
September 3, 2025 at 8:00 AM
The Lazarus group has evolved its infection chain, utilizing both old and new malware in a recent attack campaign targeting employees in defense and aerospace sectors through fake job offers, showcasing their adaptive tactics. #CyberSecurity #LazarusGroup securelist.com/lazarus-new-...
Lazarus targets nuclear-related organization with new malware
Lazarus targets employees of a nuclear-related organization with a bunch of malware, such as MISTPEN, LPEClient, RollMid, CookieTime and a new modular backdoor CookiePlus.
securelist.com
December 20, 2024 at 6:58 AM
BitMEX investigation reveals security flaws in Lazarus Group's crypto hacking: exposed IPs, Supabase access, and location in Jiaxing, China. The North Korean group employs both social engineering & sophisticated code exploits. #cryptocurrency #security #LazarusGroup
May 31, 2025 at 5:04 PM
Uncovered: Lazarus Group's #APT38 uses Cosmic Rust malware to target macOS devices, linking back to known C&C servers. This highlights ongoing threats from North Korean hackers involved in global financial attacks. 💻💥 #LazarusGroup #Korea www.hendryadrian.com/apt38-infras...
APT38 Infrastructure Hunt Uncovers macOS Malware
North Korean threat actor Lazarus Group and its financially motivated subgroup APT38 (Bluenoroff) have conducted extensive cyberattacks targeting financial institutions worldwide, including the notabl...
www.hendryadrian.com
June 28, 2025 at 10:33 PM
Six malicious packages have been identified on npm (Node package manager) linked to the notorious North Korean hacking group Lazarus. #LazarusGroup #CyberAlerts www.bleepingcomputer.com/news/securit...
North Korean Lazarus hackers infect hundreds via npm packages
Six malicious packages have been identified on npm (Node package manager) linked to the notorious North Korean hacking group Lazarus.
www.bleepingcomputer.com
March 12, 2025 at 8:52 PM
2/ oops i realized i only posted an excerpt of the #bybit / #northkorea hack interview. here's the whole thing:

https://www.youtube.com/watch?v=QzIUTSnVUko

#infosec #lazarusgroup #dprk #crypto #cybersecurity
March 3, 2025 at 11:06 PM
🔍 كشفت #BitMEX عن ثغرات أمنية في عمليات مجموعة Lazarus المرتبطة بكوريا الشمالية، منها تسريب عنوان IP حقيقي وقاعدة بيانات Supabase. يشير التحقيق إلى انقسام المجموعة إلى فرق فرعية ذات قدرات مختلفة. #Cybersecurity #LazarusGroup #Crypto #DeFi
May 31, 2025 at 5:27 PM
Bybit, one of the largest cryptocurrency exchanges, has suffered a $1.5 billion hack — the biggest crypto heist in history.

#Bybit #CryptoHack #LazarusGroup #Bitcoin #Ethereum #CyberSecurity #Blockchain #CryptoNews #TechNews #NorthKorea
February 22, 2025 at 4:34 PM
🚨 Lazarus Group Targets Nuclear Engineers.

Using trojanized VNC tools masked as aerospace job assessments, they’ve unleashed a new modular malware—CookiePlus—to evade detection. #LazarusGroup #Malware #CyberAttacks
thehackernews.com/2024/12/laza...
Lazarus Group Spotted Targeting Nuclear Engineers with CookiePlus Malware
Lazarus Group's CookiePlus malware targets nuclear engineers, showcasing DPRK's evolving arsenal and $1.34B in 2024 crypto thefts.
thehackernews.com
December 22, 2024 at 6:53 AM
North Korean #LazarusGroup drops malware via fake npm packages to steal dev credentials, expanding cyber‑espionage that threatens global tech supply chains and signals a new front in the #NorthKorea‑US conflict. #Cyberwar https://hackread.com/lazarus-group-npm-brandjacking-target-developers/
Lazarus Group Uses npm Brandjacking Campaign to Target Developers
North Korean Lazarus Group targets npm developers with brandjacking packages that mimic trusted tools, drop malware and put credentials at risk.
hackread.com
June 5, 2026 at 11:23 AM
The US Treasury sanctioned a 3rd crypto mixer used by the Lazarus Group for alleged money laundering, adding it to the SDN list. #CryptoNews #USTreasury #LazarusGroup According to CryptoPotato.
US Treasury Sanctions 3rd Crypto Mixer Used by the Lazarus Group
The US Treasury sanctioned a 3rd crypto mixer used by the Lazarus Group for alleged money laundering, adding it to the SDN list. #CryptoNews #USTreasury #LazarusGroup According to CryptoPotato.
cryptonews.blue
December 3, 2023 at 2:11 PM
📢 Independent investigator #ZachXBT has linked the $1.4B #Bybit hack to Lazarus Group, tying yet another massive crypto heist to the state-backed cybercriminals. 💰💻

Read: hackread.com/investigator...

#CyberSecurity #Crypto #ByBitHack #NorthKorea #LazarusGroup
Investigators Link $1.4B Bybit Hack to North Korea’s Lazarus Group
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
February 23, 2025 at 8:29 PM
"Researchers Capture Lazarus APT's Remote-Worker Scheme Live on Camera"

#CyberSecurity #LazarusGroup #LaptopFarms #ITrecruitment #Pattern ... thehackernews.com/2025/12/rese...
December 12, 2025 at 5:20 PM
Lazarus Group (North Korea) linked to 6 malicious npm packages! 🚨 Socket found they create backdoors & steal credentials, targeting crypto wallets (Solana, Exodus) & browser data (Chrome, Brave, Firefox). Uses typosquatting (e.g., is-buffer-validator). Beware! #security #npm #lazarusgroup
March 12, 2025 at 3:48 PM