Lazarus Group is a long-running North Korean state-sponsored threat actor attributed to the DPRK's Reconnaissance General Bureau. Under its umbrella sit financially-motivated subclusters — APT38 (bank/SWIFT heists and ATM cash-outs), BlueNoroff, and the TraderTraitor cluster (cryptocurrency and Web3/blockchain targeting) — as well as espionage and destructive operations. The group is responsible for some of the most consequential cyber events of the past decade, including the 2014 Sony Pictures attack, the 2016 Bangladesh Bank SWIFT heist, the 2017 WannaCry ransomware outbreak, and record-breaking cryptocurrency thefts culminating in the ~$1.5 billion Bybit heist of February 2025.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
+180 more relationships — see the relationships browser.
The Lazarus Group name emerged from investigations into a decade of DPRK-linked intrusions. Early activity attributed to the umbrella includes DDoS campaigns against South Korean and U.S. targets (Operation Troy, circa 2009-2013) and the destructive DarkSeoul wiper attacks (2013). The group achieved global notoriety in November 2014 with the destructive intrusion into Sony Pictures Entertainment (self-styled 'Guardians of Peace'), which the FBI publicly attributed to North Korea and which combined data theft, leaks, and wiper-based sabotage.
Around 2014-2015 a distinctly financially-motivated subcluster — tracked by Mandiant/FireEye as APT38 (MITRE G0082) and overlapping with Kaspersky's BlueNoroff — began systematically targeting banks, the SWIFT interbank messaging system, ATMs and casinos. Its signature operation was the February 2016 Bangladesh Bank heist, in which fraudulent SWIFT transactions attempted to move nearly $1 billion from the bank's account at the Federal Reserve Bank of New York; roughly $81 million was successfully stolen. APT38 has been tied to attempted or successful thefts from financial institutions in at least 38 countries (e.g. Bancomext in Mexico and Banco de Chile), and CISA has documented its 'FASTCash' ATM cash-out scheme (tracked as BeagleBoyz).
In May 2017 the group unleashed WannaCry, a self-propagating ransomware worm that used the EternalBlue SMB exploit to infect hundreds of thousands of systems worldwide, notably disrupting the UK's National Health Service. The U.S. and UK governments publicly attributed WannaCry to North Korea/Lazarus in December 2017. In September 2018 the U.S. DOJ charged DPRK programmer Park Jin Hyok in connection with Sony, WannaCry and the Bangladesh Bank heist; a February 2021 superseding indictment added two more DPRK operatives and detailed cryptocurrency thefts and the malicious 'Marine Chain' token scheme, formally linking the activity to RGB units.
From roughly 2017 onward the group pivoted heavily toward cryptocurrency and blockchain targets. BlueNoroff and the cluster CISA named 'TraderTraitor' (advisory AA22-108A, April 2022) targeted cryptocurrency exchanges, DeFi platforms, blockchain and Web3 companies, frequently using social-engineering lures — fake job offers, trojanized trading/crypto applications, and spear-phishing of developers and employees. Landmark crypto thefts attributed to the DPRK clusters include the ~$620 million Axie Infinity/Ronin bridge theft (March 2022, jointly attributed to Lazarus by the U.S. Treasury/FBI) and numerous exchange and bridge compromises. This trajectory culminated in the February 2025 Bybit heist, in which attackers compromised the Safe{Wallet} multisig signing workflow to reroute a cold-to-hot wallet transfer, stealing roughly $1.5 billion in crypto assets — the largest cryptocurrency theft on record. The FBI publicly attributed the Bybit heist to the TraderTraitor cluster (Lazarus/APT38) on February 26, 2025, and released Ethereum addresses used for laundering. The group remains highly active as of 2025-2026.
MENA relevance: The RaqibCTI record's UAE country tag reflects REAL, corroborated targeting rather than an aggregator artifact — Bybit, the victim of the February 2025 ~$1.5B heist attributed by the FBI to this actor's TraderTraitor cluster, is headquartered in Dubai, UAE (the FBI/press characterized it as a 'Dubai-based firm'), making the UAE a confirmed victim location; more broadly, the Gulf's dense concentration of cryptocurrency exchanges, Web3 firms and financial institutions makes the UAE a high-plausibility ongoing target set for this actor (VERDICT: UAE tag = REAL/CONFIRMED via the Bybit victim nexus; wider or repeated UAE targeting beyond Bybit is plausible but should be treated as MEDIUM confidence absent additional named victims).
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.