Actor
Lazarus Group
Lazarus Group is an umbrella attribution and sanctions label used for North Korean cyber actors associated with the Reconnaissance General Bureau. United States authorities have linked the label to disruptive attacks, bank theft, cryptocurrency theft and money laundering. The exact organisational boundaries and mapping of particular operations remain partly contested.
Identity and state nexus
The United States Treasury designated Lazarus Group, Bluenoroff and Andariel on 13 September 2019 and described their relationships to the Reconnaissance General Bureau (Treasury, 2019). This is an administrative attribution and sanctions record. It does not establish that Lazarus Group is one incorporated body, headquarters or operational unit responsible for every campaign associated with the wider North Korean cyber ecosystem.
Lazarus Group, Bluenoroff, Andariel, APT38, TraderTraitor and HIDDEN COBRA are labels used by different government and cybersecurity sources. Their mappings can overlap without becoming interchangeable. Named Reconnaissance General Bureau units and individual officers also require separate identification.
The United States state-nexus assessment is direct, while operation-to-cluster mapping varies. A 2021 joint advisory by the Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation and Treasury attributes specified AppleJeus cryptocurrency malware activity and documents observed techniques (AA21-048A). Technical indicators, vendor clustering, government attribution and judicial process remain separate evidence layers.
Operations and revenue generation
The public record traces a progression from disruptive attacks to bank and cryptocurrency theft. The 2021 United States indictment alleges that three named North Korean military hackers participated in a wide range of cyberattacks and financial crimes, including the Bangladesh Bank operation (Department of Justice, 17 February 2021; indictment). The charges are allegations. The defendants retain the presumption of innocence.
For Bangladesh Bank, attempted transfer instructions, funds transferred, recoveries and final loss are different figures. The near-USD 1 billion amount concerns attempted instructions, not the achieved theft. Other incidents, including Sony Pictures, WannaCry and the Ronin bridge theft, also require their own attribution, amount and legal-status records.
On 26 February 2025, the Federal Bureau of Investigation attributed the theft of approximately USD 1.5 billion from Bybit on or about 21 February to the Democratic People's Republic of Korea and identified the activity as TraderTraitor (FBI, 2025). This does not make TraderTraitor identical to every actor described as Lazarus Group. Claims that a theft was the largest ever require a defined dataset and comparison date.
Statecraft relevance and response
Cyber theft functions as state-directed revenue generation and sanctions adaptation where state direction and revenue purpose are established. Sanctions pressure does not alter the criminal character of the conduct. In May 2022, the Office of Foreign Assets Control added identified virtual-currency addresses to its Lazarus Group record (OFAC, 6 May 2022). Address designation, attribution and proof of ownership remain distinct.
The Multilateral Sanctions Monitoring Team reported in October 2025 on North Korean sanctions violations and evasion through cyber and information-technology worker activity (MSMT Report No. 2). It is a separate eleven-state mechanism, not the former United Nations Panel of Experts. Treasury's 8 July 2025 action supplies a current United States description of named information-technology worker revenue networks and their alleged Reconnaissance General Bureau relationship. Government assessments that stolen funds support prohibited programmes should not be converted into transaction-level proof of the end use of every stolen asset.
See also
North Korean cryptocurrency theft campaign (2017-present) · Bangladesh Bank heist (2016) · North Korea · Cryptocurrency and stablecoin sanctions evasion · Cryptocurrency mixers and tumblers (Tornado Cash, Blender.io) · Blockchain analytics platforms (Chainalysis, Elliptic, TRM) · Offensive cyber tools against financial infrastructure · SWIFT · Economic statecraft
Sources
- United States Department of the Treasury, Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups (13 September 2019).
- United States Department of Justice, Three North Korean Military Hackers Indicted in Wide-Ranging Scheme to Commit Cyberattacks and Financial Crimes Across the Globe (17 February 2021).
- United States v Jon Chang Hyok, Kim Il and Park Jin Hyok, Indictment, No. 2:20-cr-00614 (Central District of California, filed 8 December 2020, unsealed 17 February 2021).
- Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation and United States Department of the Treasury, AppleJeus: Analysis of North Korea's Cryptocurrency Malware, AA21-048A (17 February 2021).
- Office of Foreign Assets Control, Cyber-related Designation; North Korea Designation Update (6 May 2022).
- Federal Bureau of Investigation, North Korea Responsible for USD 1.5 Billion Bybit Hack (26 February 2025).
- Multilateral Sanctions Monitoring Team, The DPRK's Violation and Evasion of UN Sanctions through Cyber and Information Technology Worker Activities, Report No. 2 (22 October 2025).
- United States Department of the Treasury, Sanctions Imposed on DPRK IT Workers Generating Revenue for the Kim Regime (8 July 2025).
Recommended citation
Cite this entry
Tennant, James J., ed. 'Lazarus Group.' The Encyclopedia of Economic Statecraft, version 2.0.0-alpha, last reviewed 29 July 2026. https://jamesjtennant.com/entries/lazarus-group/.
Suggest an edit