How Lazarus Group laundered $200M from 25 hacks

2024-04-29 Zach XBT

https://zachxbt.mirror.xyz/B0-UJtxN41cJhpPtKv0v2LZ8u-0PwZ4ecMPEdX4l8vE

Thumbnail for How Lazarus Group laundered $200M from 25 hacks

ZachXBT traces roughly $200 million stolen across 25 cryptocurrency hacks from August 2020 to October 2023 to Lazarus Group, also described as Bluenoroff or APT38, a North Korea-linked financially motivated threat group. The investigation follows thefts affecting exchanges, DeFi projects, and individuals, including CoinBerry, Unibright, CoinMetro, Nexus Mutual, and EasyFi, with incidents involving hot-wallet breaches, private-key compromise, malicious transaction approval, and modified MetaMask activity. On-chain analysis shows stolen funds moving through intermediary wallets, Tornado Cash, ChipMixer, and Ren Protocol before consolidation and conversion paths involving Paxful, Noones, Bixin, and China-based OTC trader Wu Huihui. The excerpt provides multiple wallet addresses, mixer deposit and withdrawal transactions, and timing correlations used to support demixing and attribution confidence. The findings matter because they map a multi-year laundering playbook for DPRK-linked cryptocurrency thefts and identify exchange and OTC cash-out points used after mixing and bridging.

Indicators of Compromise

Type Value First Seen Last Seen
HASH eb4854fb3ea8a3f5d87331b04bfc4da… 2024-04-29 2024-04-29
HASH ffeb3dd56d0bde492cd08c0975edad3… 2024-04-29 2024-04-29
HASH 3e3b2950c72f863642db0a1bd248be3… 2024-04-29 2024-04-29
HASH 18b9481573afb349c499ed5469ed903… 2024-04-29 2024-04-29
HASH 906b3436067e48f3355f8cb5266c005… 2024-04-29 2024-04-29
HASH 84b7c4a2b79d454bbb1636d6d872ed3… 2024-04-29 2024-04-29
HASH db0cd0f1cb5bd13b9b3249e6a560aae… 2024-04-29 2024-04-29
HASH 0b6b1a990b6aab6edaef925c4af2a03… 2024-04-29 2024-04-29
HASH a88a7d86bbd780f42850472feffcb62… 2024-04-29 2024-04-29
HASH a63eea88c4f9304e7e6c582a586b720… 2024-04-29 2024-04-29
HASH 1586fec6363ba1d6bac3056e4aee0bc… 2024-04-29 2024-04-29
HASH 1aa32442bfcbee3981e038d50a05885… 2024-04-29 2024-04-29
HASH 5ce61bc9bec2ff7a5291b48903441a3… 2024-04-29 2024-04-29
HASH 9726abb675bff14f512018a583693e8… 2024-04-29 2024-04-29
HASH 0a6f220fdc821ec1743a9a201e16a03… 2024-04-29 2024-04-29
HASH 4e35b2214a12f8d49cdd0100d71f757… 2024-04-29 2024-04-29
DOMAIN mgnr.io 2021-11-05 2024-04-29

Related Reports

« Back