Home > Top > Body

There's More to North Korea's Hacking Ops Than Just Lazarus Group: Paradigm

clock
2025-04-01 03:36:22

In February, North Korean hackers broke headlines with what is now regarded as the largest single hack in crypto history.

The Lazarus Group stole at least $1.4 billion from Bybit and later funneled those funds to crypto mixers.

"Someone had pulled off the biggest hack in [crypto] history, and we had a front-row seat," Samczsun, Research Partner at Paradigm, recalled in a blog post.

The researcher said they witnessed the theft in real-time and collaborated with Bybit to confirm the unauthorized access.

Samczsun was working with SEAL 911, an emergency response unit affiliated with the Security Alliance, a nonprofit organization dedicated to securing decentralized systems.

But these attacks aren't all just about the Lazarus Group. There's more to North Korea's cyber offensives than previously thought.

There's a misconception about how to "classify and name” the group's operations.

While the term "Lazarus Group" is "colloquially acceptable," discussing how the DPRK (Democratic People's Republic of Korea) runs its cyber operations on the offensive needs more rigor, Samczsun claimed.

Lazarus Group has become the preferred term by the media when describing DPRK cyberactivity. Cybersecurity researchers "created more precise designations" to show which ones are working on specific activities, they added.

The DPRK's hacking ecosystem operates under the Reconnaissance General Bureau (RGB), which houses several distinct groups: AppleJeus, APT38, DangerousPassword, and TraderTraito

These groups operate with specific targeting methodologies and technical capabilities.

TraderTraitor, identified as the most sophisticated DPRK actor targeting the crypto industry, focuses on exchanges with large reserves and employs advanced techniques, successfully compromising Axie Infinity through fake job offers and manipulating WazirX.

AppleJeus specializes in complex supply chain attacks, including the 2023 3CX hack that potentially affected 12 million users.

Dangerous Password, meanwhile, conducts lower-end social engineering through phishing emails and malicious messaging on platforms like Telegram.

Another subgroup, APT38, spun out of Lazarus in 2016 and focused on financial crimes. It first targeted traditional banks before shifting attention to crypto platforms.

In 2018, the OFAC first mentioned "North Korean IT workers," which in 2023 were identified by researchers as "Contagious Interview" and "Wagemole," operating through schemes where the threat actors either pose as recruiters or attempt to get hired by target companies.

While the DPRK has shown its ability to deploy zero-day attacks, there have been "no recorded or known incidents" of it deploying directly against the crypto industry, Samczsun said.

The researcher urged crypto companies to implement basic security practices such as least privilege access, two-factor authentication, and device segregation. If preventive measures fail, connecting with security groups like SEAL 911 and the FBI's DPRK unit would also be helpful.

"DPRK hackers are an ever-growing threat against our industry, and we can't defeat an enemy that we don't know or understand," Samczsun wrote.

Edited by Sebastian Sinclair

Web3 Desktop Trading Tool
Stay ahead of the game in the cryptocurrency space.

7x24 Newsflash

14:28 2025-06-12
Sonic Labs has invested 400,000 S tokens in Hey Anon
Sonic Labs announced in a post on the X platform that it has invested 400,000 S tokens in the Hey Anon project through its Sonic Innovator Fund. Hey Anon is an on-chain AI protocol that aims to redefine users' interaction patterns with DeFi on Sonic.
14:13 2025-06-12
Hong Kong Customs has teamed up with the University of Hong Kong to develop a cryptocurrency tracking tool
The Hong Kong Customs and Excise Department has teamed up with the University of Hong Kong to develop a cryptocurrency transaction tracking tool to tackle the growing number of digital asset money laundering cases. Assistant Commissioner of Customs and Excise Wong Ho-yin said the move was aimed at cracking down on cross-border financial crimes. Between 2021 and May 2025, Hong Kong reportedly recorded 39 major money laundering cases, seven of which involved cryptocurrencies, including one suspici...
14:13 2025-06-12
WLFI official website has added exchange, lending and APP modules, and the functions are not yet open
The WLFI official website has been updated with new exchange (Swap), lending and WLFI APP modules. At present, the above functions are still in the pre-announced state and have not been officially turned on.
14:04 2025-06-12
Analysis: 20 times leverage BTC giant whale identity as Aguila Trades
According to Lookonchain monitoring, the mysterious whale address 0x1f25 has been identified as X user @AguilaTrades. In the past 4 days, it has transferred 29.85 million USDC from Bybit to Hyperliquid for 20x leverage to go long BTC. At present, it has lost more than 5.50 million dollars - but when the price of Bitcoin fell again, it chose to increase its position and continue to go long.
13:46 2025-06-12
Goldman Sachs: Lower the probability of a 12-month U.S. recession from 35% to 30%.
Goldman Sachs: Lower the probability of a 12-month U.S. recession from 35% to 30%.
13:31 2025-06-12
Trident Announces $500 million Funding Plan for XRP Vault
According to BWENEWS, Trident announced plans to raise up to $500 million for XRP Vault and appointed Chaince Securities LLC as strategic advisor.
13:21 2025-06-12
JPMorgan Chase, Chainlink and Ondo Finance complete cross-chain payment settlement test
According to Cointelegraph, Chainlink, JPMorgan's Kinexys, and Ondo Finance have completed a "first-of-its-kind" cross-chain payment delivery (DvP) settlement test, enabling the exchange of assets between a licensed payment network and a public test network. According to Chainlink, the test involved Kinexys Digital Payments, a permissioned network operated by JPMorgan, and the Ondo Chain testnet focused on real-world asset (RWA) tokenization. The settlement was conducted by Chainlink's Runtime E...
13:06 2025-06-12
Hong Kong Securities Supervision Commission Huang Tianyou: We are considering comprehensively optimizing the Shanghai, Shenzhen and Hong Kong Stock Connect, and studying and adjusting the number of shares traded per lot in Hong Kong stocks
At the Asian Traders Forum Annual Conference and Stock Trading Summit 2025, Huang Tianyou, chairperson of the Hong Kong Securities Supervision Commission, said that the Hong Kong Securities Supervision Commission, in cooperation with the Hong Kong Stock Exchange, will reduce the minimum up and down price of applicable securities by 50% to 60% in two phases starting from mid-2025, thereby reducing overall trading costs and improving liquidity. In the medium and long term, the Hong Kong Securities...
13:03 2025-06-12
Golden Evening News | List of important developments on the evening of June 12
12:00-21:00 Keywords: Antnoidae, DXY, Meta, BlackRock 1. Ant Digital starts applying for a Hong Kong stablecoin license Traders once again fully priced in the Federal Reserve's two interest rate cuts this year 3. The dollar index DXY fell 1.00% in the day and is now at 97.65. 4. Binance HODLer Airdrop Launches Defi App (HOME) 5. US senators investigate Facebook parent company Meta's stablecoin plan 6. BlackRock: Aims to become the world's largest crypto asset manager by 2030
12:54 2025-06-12
Cross-border e-commerce company DDC Enterprise increases its holdings of 38 BTC, bringing its total holdings to 138 BTC.
Cross-border e-commerce company DDC Enterprise announced the addition of 38 bitcoins to the company's vault, bringing its total holdings to 138 BTC. Since May this year, its bitcoin investment has achieved a 22% return. The company said it will continue to implement a strict bitcoin accumulation strategy, further strengthening its strategic goal of becoming the world's top corporate treasury.
12:54 2025-06-12
US PPI remains moderate in May, tariff effect or "late strike"
Core US PPI data for May fell short of expectations on the modest impact of the cost of goods and services, the Bureau of Labor Statistics reported on Thursday. Although the impact of higher tariffs on Americans is not yet significant, economists pointed out that price pressures could intensify in the second half of the year as companies try to avoid further weakening margins. PPI data showed that wholesalers and retailers' profit margins rose in May after falling in April.
12:42 2025-06-12
Spot gold hit $3,390, up more than 1% in the day.
Spot gold rallied upward, hitting $3,390/ounce, up more than 1% during the day.