The total take for the Lazarus hackers was over 400,000 ETH and stETH valued at about $1.5 billion in total. The public report of the crypto theft triggered a wave of about 580,000 withdrawal requests. Bybit says that it has weathered that bank run.
Lazarus APT targets the employees of blockchain companies with fake job offers, tricking them into downloading trojanized apps that steal security keys and make fraudulent transactions.
The US Treasury Department has linked North Korea's state-sponsored Lazarus hacking group to the $625 million breach of the Ronin network. The crypto theft was the largest to ever happen to a DeFi platform in terms of unrecovered funds.
North Korean Hacker Charged for 2022 Ransomware Attacks on US Hospitals, Data Theft From US Military
A North Korean hacker responsible for a trail of massive damage to hospitals and the US military has been unmasked, as a federal grand jury has indicted Rim Jong Hyok in a 2022 string of thefts of data from the US government and ransomware attacks in the healthcare sector.
A phishing campaign by the North Korean government-linked hacking group Kimsuky is leveraging a malicious Chrome extension to steal Gmail emails from high-value targets.
North Korean hackers have now plundered $2 billion this year and an overall total of $6 billion in stolen crypto. The state-sponsored hacking teams have demonstrated creative means of penetrating crypto platforms and are responsible for at least 30 incidents in 2025, including a $1.46 billion theft from Bybit.
North Korea's new record for stolen crypto, $1.34 billion, represents 61% of the total of about $2.2. billion stolen in 2024. Skilled state-backed North Korean hackers are almost single-handedly keeping numbers above the $1 billion level globally.
North Korean hackers intensify their efforts against blockchain and Web3 developers, using nearly 200 malicious npm packages in the ongoing Contagious Interview hacking campaign.
North Korean hackers are using ClickFix social engineering tactics to compromise devices and perform data exfiltration in a highly focused cyber espionage campaign.
Lazarus hacking group found to be developing capabilities in supply chain attacks and using the MATA framework to conduct cyber espionage on the defense industry.










