Lazarus Group (APT38 / Hidden Cobra / BlueNoroff)
Prolific state-backed cyber warfare and financial cyber-heist collective responsible for billions in cryptocurrency theft, defense espionage, and disruptive attacks.
Operating under the Reconnaissance General Bureau (RGB), Lazarus blends destructive malware capabilities with sophisticated financial fraud, targeting cryptocurrency exchanges, DeFi protocols, defense contractors, and SWIFT banking networks globally.
Exfiltration of $340M in digital assets utilizing social engineering over developer messaging channels and trojanized Web3 SDKs.
Compromise of validator private keys resulting in $620M asset extraction.
Fraudulent SWIFT order injection attempting to steal $951M ($81M successfully moved).
Destructive wiper attack destroying internal corporate infrastructure and leaking unreleased films.
United States v. Jon Chang Hyok et al.
APT38: Un-bankable State-Sponsored Financial Cybercrime