How the Lazarus Group is stepping up crypto hacks and changing its tactics
2023-09-15 • Elliptic •
The elite North Korean hacking group Lazarus appears to have recently ramped up its operations, conducting a confirmed four attacks against crypto entities since June 3rd. They are also likely to operate using centralized internal information technology systems, allowing Lazarus malware a greater chance to penetrate the intended functions of their business. In the past 104 days, Lazarus has already been identified as responsible for stealing almost $240 million in crypto assets from Atomic Wallet ($100m) CoinsPaid ($37.3M), Alphapo ($60M), and Stake.com ($41M). Elliptic attributed this hack to Lazarus on 06 June 2023, after identifying multiple factors indicating that the North Korean threat group was responsible.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | stake.com | 2023-09-05 | 2025-12-31 |