North Korean state-sponsored threat actors, including the Lazarus Group and Kimsuky, have been responsible for a dramatic surge in global cryptocurrency theft in 2025, stealing at least $2.02 billion—over half of the total $3.4 billion stolen worldwide. The February compromise of the Bybit cryptocurrency exchange accounted for $1.5 billion of these losses, with the attack attributed to the TraderTraitor cluster, and further links established through malware infrastructure analysis. Lazarus Group, affiliated with North Korea's Reconnaissance General Bureau, has also been implicated in the theft of $36 million from Upbit and is estimated to have stolen over $6.75 billion cumulatively through a series of high-profile heists and campaigns.
Recent collaborative research by Hunt.io and the Acronis Threat Research Unit has uncovered new operational infrastructure used by both Lazarus and Kimsuky across global campaigns. The investigation revealed active tool-staging servers, credential theft environments, and tunneling nodes, highlighting the interconnected nature of DPRK cyber operations. Despite evolving malware and tactics, these groups consistently reuse infrastructure, making their activities traceable across campaigns. The findings provide defenders with actionable intelligence on the infrastructure patterns and operational habits of North Korean threat actors, supporting efforts to detect and disrupt ongoing and future attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Chainalysis and follow-on reporting said North Korean operators increasingly relied on IT worker infiltration, recruiter and investor impersonation, and executive-targeted social engineering to gain access. The reports also described laundering through Chinese-language services, mixers, bridges, DeFi protocols, and weak-KYC exchanges, often completing fund movement within about 45 days.
The same 2025 Chainalysis assessment said attacks on individual wallets rose sharply to about 158,000 incidents affecting roughly 80,000 victims. It also described a tactical shift toward fewer but larger compromises of centralized services alongside broad wallet targeting.
On December 18, 2025, Chainalysis reported that North Korean threat actors stole at least $2.02 billion in cryptocurrency in 2025, a 51% increase from the prior year. The report said DPRK-linked actors were responsible for 76% of all crypto service compromises by value and brought their cumulative theft total to $6.75 billion.
Using an FRP binary hash, researchers found eight internet-facing hosts serving an identical FRP binary on port 9999. The matching deployments were assessed as consistent with scripted provisioning of tunneling infrastructure used in DPRK operations.
The Hunt.io and Acronis investigation identified a new Linux variant of the Lazarus-associated BADCALL backdoor hosted on an exposed open-directory server. Researchers noted a functional update in the malware that adds logging to /tmp/sslvpn.log.
A joint Hunt.io and Acronis Threat Research Unit investigation published in December 2025 mapped ongoing DPRK-linked infrastructure by pivoting across IPs, open directories, certificates, and file hashes. The research identified recurring patterns including exposed tool-staging directories, repeated credential-theft toolkits, uniform FRP tunneling deployments, and certificate reuse linking separate clusters.
Chainalysis highlighted a September 2025 Venus Protocol incident in which rapid detection and response prevented major losses and even caused losses for the attacker. The case was cited as evidence that faster defensive action can blunt large-scale crypto theft attempts.
In February 2025, attackers linked to North Korea stole about $1.5 billion from the Dubai-based Bybit exchange. Multiple sources describe it as the largest single cryptocurrency theft of the year and the dominant contributor to DPRK-attributed losses in 2025.
Hunt.io and Acronis said a pivot from the Lazarus-linked domain secondshop[.]store to a reused TLS certificate common name uncovered 12 RDP-exposed IPs active since January 2025. Ten of those hosts were correlated with Lazarus malware on port 443, while two also overlapped with Bluenoroff/APT38 tracking.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
coindesk.com
Open sourcetomshardware.com
Open sourcedarkreading.com
Open sourcego.theregister.com
Open sourcetherecord.media
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcechainalysis.com
Open sourcehunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.