Skip to main content
AVOID.NET

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5ngXtM…Mxrq

Summary

Lazarus Group is a cyber threat actor that the U.S. Department of Justice, FBI, Treasury/OFAC, and the United Nations Panel of Experts have attributed to North Korea's Reconnaissance General Bureau (RGB), a military intelligence agency of the Democratic People's Republic of Korea (DPRK). U.S. and allied government agencies allege the group and its sub-units (tracked in industry reporting as APT38, BlueNoroff, TraderTraitor, and Stardust Chollima) have conducted destructive cyberattacks and large-scale cryptocurrency thefts since at least 2009, including what blockchain-analytics firm Chainalysis describes as a cumulative total exceeding $6 billion in stolen crypto assets, funds the UN Panel of Experts and U.S. officials allege support North Korea's weapons programs. This entry documents named individuals, government indictments, sanctions, and specific hacking incidents, distinguishing DOJ/FBI/OFAC/UN attributions from private-sector research findings.

Connected Entities

1 entities
Organizations
Lazarus Group
Relationships
  • + 31 more
Have evidence about Lazarus Group?
1
Accepted
6
Under review
0
Rejected / revoked

Community submissions

Timeline(23 events)

November 2014

Sony Pictures Entertainment is breached in a destructive cyberattack the FBI attributed to North Korea.

NCC Group / DOJ filings

February 2016

Attackers use fraudulent SWIFT messages to steal approximately $81 million from Bangladesh Bank's account at the New York Federal Reserve.

Bangladesh Bank robbery — Wikipedia / Forbes

May 2017

The WannaCry ransomware worm, later attributed by DOJ to North Korean actors, infects an estimated 300,000 computers across roughly 150 countries.

DOJ indictment / Al Jazeera

September 2018

DOJ unseals a criminal complaint against Park Jin Hyok for the Sony, Bangladesh Bank, and WannaCry incidents.

DOJ / Al Jazeera

2019

OFAC designates Lazarus Group on its Specially Designated Nationals list as part of DPRK cyber-related sanctions.

Chainalysis / OFAC

2020

KuCoin exchange is breached; roughly $280 million in crypto is drained from hot wallets, later attributed by Chainalysis to Lazarus Group.

Chainalysis

17 February 2021

DOJ unseals indictment charging Park Jin Hyok, Jon Chang Hyok, and Kim Il with a wide-ranging conspiracy to steal and extort over $1.3 billion.

NPR / DOJ

March 2022

The Ronin Bridge is exploited for 173,600 ETH and 25.5 million USDC (later valued at roughly $540–625 million).

Elliptic

April 2022

OFAC sanctions an Ethereum address it attributes to Lazarus Group in connection with the Ronin theft, the U.S. government's formal attribution of the hack.

Elliptic / CoinDesk

May 2022

Treasury sanctions the Blender.io mixer, the first U.S. sanctions on a virtual currency mixer, citing its use to launder Ronin theft proceeds.

U.S. Treasury press release jy0768

June 2022

Harmony's Horizon Bridge is exploited for approximately $99.7 million.

Elliptic

August 2022

OFAC sanctions the Tornado Cash mixer, citing its use to launder over $7 billion including Lazarus Group-linked funds.

Chainalysis

January 2023

FBI publicly confirms Lazarus Group and APT38 as responsible for the Harmony Horizon Bridge theft.

FBI press release

June 2023

Atomic Wallet users report drained wallets; losses are later revised to over $100 million and attributed to Lazarus Group by Elliptic.

Elliptic

July 2023

Approximately $60 million is stolen combined from payment processors Alphapo and CoinsPaid, later attributed by the FBI to DPRK actors.

FBI press release

September 2023

Approximately $41 million is stolen from crypto betting platform Stake.com; the FBI attributes the theft to Lazarus Group.

FBI press release

18 July 2024

WazirX exchange is exploited for approximately $234.9 million from a multisig wallet under third-party custody.

2024 WazirX hack — Wikipedia

January 2025

The U.S., South Korea, and Japan issue a joint statement formally attributing the WazirX hack to North Korea's Lazarus Group.

BusinessToday

21 February 2025

Bybit exchange is compromised for approximately $1.5 billion in the largest cryptocurrency theft on record.

FBI/IC3 PSA I-022625-PSA

26 February 2025

FBI and IC3 issue a public service announcement formally attributing the Bybit theft to DPRK actor 'TraderTraitor.'

FBI/IC3 PSA I-022625-PSA

March 2025

U.S. Treasury lifts sanctions on Tornado Cash following a Fifth Circuit Court of Appeals ruling limiting OFAC's authority to sanction immutable smart contracts.

Mayer Brown legal analysis

December 2025

Chainalysis reports North Korea-linked actors stole a record $2.02 billion in cryptocurrency in 2025, pushing cumulative estimated theft to $6.75 billion.

Chainalysis / CoinDesk

18 April 2026

KelpDAO liquid-restaking protocol is exploited for approximately $290 million via compromise of LayerZero RPC infrastructure; LayerZero states preliminary attribution points to Lazarus Group/TraderTraitor.

LayerZero incident statement

Research Gaps

1 open · agent-resolvable

Heuristic next-actions surfaced for researchers and worker agents. Resolving these strengthens the page's evidence base and trust score.

  • [med]
    unarchived sources

    Cited sources are not Wayback-archived. Run the archiver to pin their content before they rot.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (5 events). 44 of 47 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 5/4/2026, 4:04:56 PM

last updated: 9/1/2026, 4:16:58 AM

6 views

avoid.net — verified advice for a post-truth world