Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagecryptocurrency-platform-risktelecommunications-sector-threatdefense-evasion-method

North Korean State-Sponsored Cyber Operations and Cryptocurrency Theft

Updated 2mo agoFirst seen Oct 27, 20254 sources

North Korean state-backed hacking groups, including Lazarus, Andariel, and Kimsuky, have been identified as leading actors in global nation-state cyberattacks, accounting for 18.2% of all such activity between April and September. These groups have adopted increasingly sophisticated tactics, such as "malware-free" intrusions, covert infiltration schemes, and the use of legitimate system tools like PowerShell and Command Prompt to evade detection. Telecommunications, technology, and transportation sectors have been the primary targets, with Turkey and the U.S. among the most frequently attacked nations. Security experts recommend layered defenses and zero-trust principles to counter these evolving threats.

A recent report by the Multilateral Sanctions and Measures Team (MSMT), with contributions from Chainalysis, reveals that North Korea has stolen an estimated $2.8 billion in cryptocurrency from January 2024 to September 2025, including a $1.5 billion heist from the Bybit exchange. The report highlights the expansion of North Korea's laundering networks, which now involve sophisticated mixing services, OTC brokers across multiple jurisdictions, and collaboration with Russian and Cambodian money laundering networks. The use of UnionPay cards and Hong Kong-based intermediaries further complicates efforts to trace and recover stolen assets, underscoring the growing scale and complexity of North Korean cyber operations.

Share:
North Korean State-Sponsored Cyber Operations and Cryptocurrency Theft
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Apr 6, 20263mo ago

DomainTools details DPRK's modular three-track malware architecture

DomainTools reported that North Korea's cyber program had evolved into a compartmentalized malware ecosystem with separate espionage, financial theft, and disruptive tracks linked to Kimsuky, Lazarus-associated actors, and Andariel. The report said this structure improves resilience against takedowns and attribution while supporting continued targeting of governments, defense firms, think tanks, crypto exchanges, and software supply chains.

DPRK Cyber Program Uses Modular Malware Strategy to Evade Attribution and Survive Takedowns
Oct 27, 20258mo ago

Reports highlight North Korea as leading state-backed cyber threat

SC Media and Chainalysis published reports emphasizing North Korea's prominent role in global state-sponsored cyber operations and cyber-enabled financial crime. The references indicate this assessment was current as of their publication date, but provide no earlier dated events to extract.

Dec 16, 20224y ago

Sekoia documents active DPRK cyber campaigns and tradecraft in 2022

Sekoia reported that throughout 2022, major DPRK-linked groups including Lazarus and Kimsuky remained active in both cyberespionage and financially motivated operations targeting cryptocurrency, fintech, aerospace, defense, diplomacy, civil society, and energy sectors. The report highlighted ongoing campaigns such as DreamJob, AppleJeus, SnatchCrypto, and TraderTraitor, along with updated malware and techniques including BYOVD, Chrome zero-day exploitation, geofencing, and IP validation.

The DPRK delicate sound of cyber - Sekoia.io Blog
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

47 LINKEDOpen in app
Affected products
9 linked
WindowsWhatsappGithubLinkedinDropboxPuttyAndroidMicrosoft OfficeMacos
Organizations
13 linked
DomainToolsBlender.ioLinkedinSekoiaDropboxMeta PlatformsTornado CashBroadcomMicrosoft CorporationGitHubSlack TechnologiesGoogleRonin Network
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.