DeFi Intel

Lazarus Group threat-group

state-actor · PageRank 0.0045

Also known as: TraderTraitor, APT38, DPRK

Source: chainalysis.com

Overview

Lazarus Group (also known as TraderTraitor, APT38, or the DPRK's primary cyber-espionage and sabotage unit) is a North Korean state-sponsored threat actor. It is associated with financially motivated cyber intrusions targeting financial institutions, cryptocurrency exchanges, and individuals, often to generate revenue for the regime. The group has been active since at least 2009 and is known for deploying advanced malware and social engineering tactics.

Within the DeFi Intel graph, Lazarus Group connects to 3 tracked entities, most strongly to Tornado Cash, Sinbad.io, Blender.io.

Relations

Top connections in the DeFi Intel knowledge graph (confidence-weighted, 3 of 3 total).

RelationConnected entityConfidence
laundered_throughTornado Cash95%
laundered_throughSinbad.io95%
laundered_throughBlender.io95%

Frequently asked questions

What is Lazarus Group?

Lazarus Group, also known as TraderTraitor, APT38, or the DPRK's primary cyber-espionage and sabotage unit, is a North Korean state-sponsored threat actor. It has been active since at least 2009 and is associated with financially motivated cyber intrusions targeting financial institutions, cryptocurrency exchanges, and individuals.

Which crypto services has Lazarus Group exploited?

Lazarus Group has exploited Tornado Cash, Sinbad.io, and Blender.io.

How much did Lazarus Group steal from KelpDAO?

Lazarus Group stole $290 million from KelpDAO via an RPC node compromise, as covered in the LayerZero Post Mortem.