Actor

Lazarus Group

Lazarus Group is an umbrella attribution and sanctions label used for North Korean cyber actors associated with the Reconnaissance General Bureau. United States authorities have linked the label to disruptive attacks, bank theft, cryptocurrency theft and money laundering. The exact organisational boundaries and mapping of particular operations remain partly contested.

Identity and state nexus

The United States Treasury designated Lazarus Group, Bluenoroff and Andariel on 13 September 2019 and described their relationships to the Reconnaissance General Bureau (Treasury, 2019). This is an administrative attribution and sanctions record. It does not establish that Lazarus Group is one incorporated body, headquarters or operational unit responsible for every campaign associated with the wider North Korean cyber ecosystem.

Lazarus Group, Bluenoroff, Andariel, APT38, TraderTraitor and HIDDEN COBRA are labels used by different government and cybersecurity sources. Their mappings can overlap without becoming interchangeable. Named Reconnaissance General Bureau units and individual officers also require separate identification.

The United States state-nexus assessment is direct, while operation-to-cluster mapping varies. A 2021 joint advisory by the Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation and Treasury attributes specified AppleJeus cryptocurrency malware activity and documents observed techniques (AA21-048A). Technical indicators, vendor clustering, government attribution and judicial process remain separate evidence layers.

Operations and revenue generation

The public record traces a progression from disruptive attacks to bank and cryptocurrency theft. The 2021 United States indictment alleges that three named North Korean military hackers participated in a wide range of cyberattacks and financial crimes, including the Bangladesh Bank operation (Department of Justice, 17 February 2021; indictment). The charges are allegations. The defendants retain the presumption of innocence.

For Bangladesh Bank, attempted transfer instructions, funds transferred, recoveries and final loss are different figures. The near-USD 1 billion amount concerns attempted instructions, not the achieved theft. Other incidents, including Sony Pictures, WannaCry and the Ronin bridge theft, also require their own attribution, amount and legal-status records.

On 26 February 2025, the Federal Bureau of Investigation attributed the theft of approximately USD 1.5 billion from Bybit on or about 21 February to the Democratic People's Republic of Korea and identified the activity as TraderTraitor (FBI, 2025). This does not make TraderTraitor identical to every actor described as Lazarus Group. Claims that a theft was the largest ever require a defined dataset and comparison date.

Statecraft relevance and response

Cyber theft functions as state-directed revenue generation and sanctions adaptation where state direction and revenue purpose are established. Sanctions pressure does not alter the criminal character of the conduct. In May 2022, the Office of Foreign Assets Control added identified virtual-currency addresses to its Lazarus Group record (OFAC, 6 May 2022). Address designation, attribution and proof of ownership remain distinct.

The Multilateral Sanctions Monitoring Team reported in October 2025 on North Korean sanctions violations and evasion through cyber and information-technology worker activity (MSMT Report No. 2). It is a separate eleven-state mechanism, not the former United Nations Panel of Experts. Treasury's 8 July 2025 action supplies a current United States description of named information-technology worker revenue networks and their alleged Reconnaissance General Bureau relationship. Government assessments that stolen funds support prohibited programmes should not be converted into transaction-level proof of the end use of every stolen asset.

See also

North Korean cryptocurrency theft campaign (2017-present) · Bangladesh Bank heist (2016) · North Korea · Cryptocurrency and stablecoin sanctions evasion · Cryptocurrency mixers and tumblers (Tornado Cash, Blender.io) · Blockchain analytics platforms (Chainalysis, Elliptic, TRM) · Offensive cyber tools against financial infrastructure · SWIFT · Economic statecraft

Sources

Recommended citation

Cite this entry

Tennant, James J., ed. 'Lazarus Group.' The Encyclopedia of Economic Statecraft, version 2.0.0-alpha, last reviewed 29 July 2026. https://jamesjtennant.com/entries/lazarus-group/.

Suggest an edit