Lazarus: Is your best IT worker really a North Korean hacker?

2025-06-11 Group-IB

https://podcasts.apple.com/us/podcast/lazarus-is-your-best-it-worker-really-a-north-korean-hacker/id1813334799?i=1000712386700

Thumbnail for Lazarus: Is your best IT worker really a North Korean hacker?

The podcast excerpt presents Lazarus as an active North Korean threat actor with past activity ranging from the Sony Pictures attack to major cryptocurrency theft such as the Bybit incident. Its current focus in the provided text is infiltration campaigns in which North Korean operators pose as remote IT employees inside companies. The described tradecraft includes using insider-style access to funnel information through backdoors and placing logic bombs in code that could be triggered months or years later. The defensive takeaway is that DPRK cyber risk can enter through hiring and software-development workflows, requiring identity verification, engineering oversight, and organization-wide vigilance for unusual behavior.

Related Actors

Related Reports

« Back