Lazarus Group just connected the Bybit hack to the Phemex hack
2025-02-22 • Zach XBT •
The archived thread reports on-chain links between the Bybit, Phemex, and BingX theft clusters attributed in the thread to Lazarus Group. It cites commingling between Bybit and Phemex theft addresses, test transactions, connected wallets used before the Bybit exploit, and later movement tying a BingX-linked address into the same cluster. The thread also references ZachXBT’s Arkham bounty submission, which it says provided transaction analysis, wallet links, forensic graphs, and timing evidence for Lazarus attribution. The value of the source is the claimed blockchain clustering rather than new malware or intrusion-chain detail.
Related Actors
Related Reports
Shares tags: Lazarus, Bybit • Published within a month
Shares tags: Lazarus, Bybit • Published within a month
Shares tags: Lazarus, Bybit • Published within a month
Shares tags: Lazarus, Bybit • Published within a week
2025-02-25 •
60% Match
Silent Push Pivots into New Lazarus Group Infrastructure, Acquires Sensitive Intel Related to $1.4B ByBit Hack and Past Attacks
Silentpush
Shares tags: Lazarus, Bybit • Published within a week
2025-02-24 •
60% Match
#Lazarus
#Bybit
#T1082
#T1046
#T1027
#T1567
#T1552
#T1566
#T1059
#T1195
#T1078
#T1530
#T1590
#T1657
#T1583
#T1068
#T1485
#T1649
#T1021
#T1592.003
Shares tags: Lazarus, Bybit • Published within a week