Lazarus Group threat-group
Overview
Lazarus Group (also known as TraderTraitor, APT38, or the DPRK's primary cyber-espionage and sabotage unit) is a North Korean state-sponsored threat actor. It is associated with financially motivated cyber intrusions targeting financial institutions, cryptocurrency exchanges, and individuals, often to generate revenue for the regime. The group has been active since at least 2009 and is known for deploying advanced malware and social engineering tactics.
Within the DeFi Intel graph, Lazarus Group connects to 3 tracked entities, most strongly to Tornado Cash, Sinbad.io, Blender.io.
Relations
Top connections in the DeFi Intel knowledge graph (confidence-weighted, 3 of 3 total).
| Relation | Connected entity | Confidence |
|---|---|---|
laundered_through | Tornado Cash | 95% |
laundered_through | Sinbad.io | 95% |
laundered_through | Blender.io | 95% |
Frequently asked questions
What is Lazarus Group?
Lazarus Group, also known as TraderTraitor, APT38, or the DPRK's primary cyber-espionage and sabotage unit, is a North Korean state-sponsored threat actor. It has been active since at least 2009 and is associated with financially motivated cyber intrusions targeting financial institutions, cryptocurrency exchanges, and individuals.
Which crypto services has Lazarus Group exploited?
Lazarus Group has exploited Tornado Cash, Sinbad.io, and Blender.io.
How much did Lazarus Group steal from KelpDAO?
Lazarus Group stole $290 million from KelpDAO via an RPC node compromise, as covered in the LayerZero Post Mortem.