Expel reported that a North Korean state-sponsored threat group linked to Lazarus is targeting Web3 developers in a campaign designed to steal cryptocurrency and non-fungible tokens (NFTs). The activity focuses on developers working in blockchain and related ecosystems, a sector that remains attractive to DPRK operators because of its direct access to digital assets and development environments.
The reporting describes the operation as part of a broader effort to industrialize social engineering and intrusion activity with AI-assisted tactics, allowing the group to scale outreach and improve the credibility of its lures. The campaign underscores Lazarus's continued focus on financially motivated operations that blend state-backed tradecraft with theft of digital assets from individuals and organizations tied to the Web3 sector.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Expel said it is tracking a North Korean state-sponsored advanced persistent threat group targeting Web3 developers. The campaign's apparent objective is to steal cryptocurrency and non-fungible tokens (NFTs).
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.