The United States has tied North Korea’s Lazarus Group and related DPRK cyber operators to a long-running campaign of financially motivated intrusions, sanctions evasion, and destructive attacks, describing the activity as a revenue source for Pyongyang’s weapons programs. U.S. government advisories and enforcement actions link the regime-backed operators—also tracked as HIDDEN COBRA—to major incidents including the Sony Pictures attack, the Bangladesh Bank SWIFT theft, WannaCry 2.0, FASTCash ATM cash-out operations, and repeated compromises of cryptocurrency businesses and exchanges.
Treasury, DOJ, and FBI actions have named and charged North Korean operatives and their facilitators, including sanctions on individuals accused of supporting Lazarus and laundering stolen virtual assets. U.S. authorities said Lazarus stole hundreds of millions of dollars from the Ronin network tied to Axie Infinity, while other cases alleged more than $100 million in cryptocurrency laundering tied to exchange hacks. Officials said the campaign has generated billions in illicit proceeds and warned that financial institutions, crypto firms, and infrastructure operators face continued risk from DPRK-linked theft, money laundering, extortion, and related cyber activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
The U.S. Treasury announced sanctions on individuals accused of laundering cryptocurrency for the Lazarus Group. The action reflected continued U.S. efforts to disrupt financial support networks for DPRK-linked cybercrime.
The U.S. Treasury sanctioned four entities and one individual for supporting North Korea’s malicious cyber operations and fraudulent overseas IT worker schemes. The action targeted organizations tied to the Reconnaissance General Bureau, including the Technical Reconnaissance Bureau, the 110th Research Center, Pyongyang University of Automation, Chinyong Information Technology Cooperation Company, and DPRK national Kim Sang Man.
The U.S. Department of Justice later charged Sim with conspiracy related to work with OTC traders, according to the report on the sanctions action. The charge was presented as an additional legal step connected to laundering support for Lazarus-linked activity.
The U.S. Treasury sanctioned three North Koreans for supporting the Lazarus Group, which it said is controlled by North Korea’s Reconnaissance General Bureau and has conducted a multibillion-dollar campaign against the cryptocurrency sector. The action highlighted allegations that stolen crypto proceeds help fund North Korea’s weapons program.
The Departments of State, Treasury, and Homeland Security, along with the FBI, issued a joint advisory describing DPRK as a significant state-sponsored cyber threat to critical infrastructure and the international financial system. The advisory publicly tied North Korea to operations including Sony, Bangladesh Bank, WannaCry, FASTCash, and exchange thefts.
A March 2020 Department of Justice forfeiture complaint alleged that North Korean cyber actors used North Korean infrastructure to hack digital currency exchanges, steal hundreds of millions of dollars in digital currency, and launder the proceeds. The complaint added legal detail to prior public allegations about DPRK crypto theft.
The UN Security Council 1718 Committee Panel of Experts’ 2019 mid-term report said it was investigating dozens of suspected DPRK cyber-enabled heists and that, as of late 2019, North Korea had attempted to steal as much as $2 billion. The report also described increasingly sophisticated laundering and theft operations.
The U.S. Treasury announced sanctions targeting North Korea for multiple cyber-attacks. The action accompanied broader U.S. efforts to impose consequences for DPRK-linked cyber operations.
The U.S. Department of Justice announced charges against a North Korean regime-backed programmer for conspiracy to conduct multiple cyber attacks and intrusions. The case tied together activity including major DPRK-linked operations.
In April 2018, DPRK state-sponsored cyber actors allegedly hacked a digital currency exchange and stole nearly $250 million in digital currency. The stolen assets were allegedly laundered through hundreds of automated transactions to obscure their origin.
In one 2018 FASTCash incident, DPRK cyber actors enabled simultaneous ATM withdrawals in 23 countries. The event was cited by U.S. authorities as part of North Korea’s ongoing financial theft operations.
In May 2017, WannaCry 2.0 infected hundreds of thousands of computers across more than 150 countries, affecting hospitals, schools, businesses, and homes. The ransomware encrypted victims’ data and demanded payment in Bitcoin.
In one 2017 FASTCash incident, DPRK cyber actors enabled simultaneous ATM withdrawals in more than 30 countries. The operation demonstrated the scale of the bank payment-switch compromise technique.
In February 2016, DPRK state-sponsored cyber actors allegedly attempted to steal at least $1 billion from financial institutions worldwide and succeeded in stealing $81 million from Bangladesh Bank. The operation used spear-phishing, compromised SWIFT-connected systems, and fraudulent authenticated transfer messages.
Since late 2016, DPRK state-sponsored cyber actors have used the FASTCash scheme to steal tens of millions of dollars from ATMs in Asia and Africa. The scheme remotely compromises banks’ payment switch application servers to enable fraudulent withdrawals.
The FBI issued an update on the Sony investigation identifying the North Korean government as responsible for the intrusion. This marked a formal U.S. law enforcement attribution of the attack.
In November 2014, DPRK state-sponsored cyber actors allegedly attacked Sony Pictures Entertainment in retaliation for the film “The Interview.” The attack involved theft of confidential data, threats to executives and employees, and damage to thousands of computers.
The Lazarus Group was identified as being behind the theft of $625 million in digital assets from the Ronin network tied to the Axie Infinity game. The theft was described as the largest-ever crypto heist.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
home.treasury.gov
Open sourcehome.treasury.gov
Open sourcecoindesk.com
Open sourceus-cert.gov
Open sourceofac.treasury.gov
Open sourceofac.treasury.gov
Open sourceofac.treasury.gov
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.