Mandiant: North Korean hackers steal cryptocurrency for the country’s needs
A cybersecurity company has uncovered hacker groups operating outside the DPRK
26.03.2022 - 09:25
846
2 min
0
ybersecurity company has uncovered hacker groups operating outside the DPRK.
What’s new? North Korea hires hackers to finance government agencies through “crypto heists.” According to a report by cybersecurity company Mandiant, the hackers are operated by RGB, North Korea’s intelligence agency (analogous to the CIA). The “Lazarus” group (the term for Korean hackers) actually has multiple units, including outside the country, Mandiant claims.
Who are Lazarus? The hackers associated with this group have been involved in hacks of crypto firms and traditional banks for several years. They were responsible for the 2016 Bangladesh bank heist and the SWIFT system’s hack. Most of these attacks have been successful, with hackers raising more than $400 million in 2021.
Recent hacker activity. Lazarus exploited vulnerabilities in the Google Chrome browser between January and February 2022. Google’s Threat Analysis Group (TAG) reported that state-backed North Korean hackers used a “remote code execution vulnerability in Chrome” for phishing attacks. More than 340 people have been affected by the attackers.
Useful material?
Incidents
Developers warned of potential risks to bridges across the ecosystem and asked exchanges for assistance.
Jun 22, 2026
Incidents
The defendant helped move funds stolen through investment scams and earned at least $4 million for his role in the operation.
Jun 10, 2026
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Telegram
Twitter