Skip to content

other

Lazarus Group

North Korean state-sponsored hacking group (APT38) known for cryptocurrency theft, bank heists, and espionage campaigns like Operation Dream Job.

Known aliases

  • APT38
  • DPRK Lazarus Group
  • Lazarus
  • Lazarus Group
  • Lazarus threat actors
  • Operation Dream Job
  • Operation Dream Job actor

Relationships

No evidence-backed relationships are recorded.

Current stories

invest5 publishers

Attacker drains $3.8 million from Near Intents via bug in Omni deposit and withdrawal layer

Near Intents halted its cross-chain swap service after a bug in its Omni deposit layer let an attacker take about $3.8 million. Crypto balances carry no deposit insurance, so affected users are relying on the operator's promise to repay them in full.

Perspective Coverage

5 publishers
Builder
Builder 23%
Operator
Operator 44%
Investor
Investor 33%

Reality

Evidence70
Adoption55
Hype gap+15
Incentives60
Confidence65
security3 publishers

Unauthenticated Dell CSM flaw leaks admin credentials for every registered storage array

Dell patched six critical flaws in its Kubernetes storage modules, one letting unauthenticated attackers pull admin credentials for every registered array. The Authorization module holds those keys for each array it fronts, so one reachable deployment exposes all the storage registered behind it.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 65%
Investor
Investor 8%

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence72
build1 publisher

Kelp DAO sues LayerZero in British Columbia over the $292M rsETH bridge exploit

Kelp DAO has sued LayerZero Labs and co-founder Bryan Pellegrino for negligence and misrepresentation over April's $292 million rsETH bridge exploit. The forged message cleared a bridge that trusted one LayerZero-run verifier, so the case tests who answers for that setup.

Publishers:dev.to

Reality

Evidence35
Adoption
Insufficient
Hype gap+15
Incentives60
Confidence35
security10 publishers

Suspected North Korean attackers used Bitget's own signing process to move $351.6M

Bitget says suspected North Korean attackers took $351.6 million from its hot and warm wallets by spoofing the transaction data that triggers its signing process. Its $464 million user protection fund, held in bitcoin, covers the loss.

Perspective Coverage

10 publishers
Builder
Builder 27%
Operator
Operator 42%
Investor
Investor 31%

Reality

Evidence55
Adoption
Insufficient
Hype gap+25
Incentives70
Confidence60
invest3 publishers

Bitget presses THORChain to cut off the wallets holding its stolen $387.5 million

Bitget CEO Gracy Chen publicly asked THORChain to refuse service to the wallets that took $387.5 million, after Circle and Tether stopped nearly $318,000. Much of the rest now depends on a no-KYC swap protocol that has declined to block stolen funds in earlier hacks, including its own.

Perspective Coverage

3 publishers
Builder
Builder 38%
Operator
Operator 40%
Investor
Investor 22%

Reality

Evidence57
Adoption44
Hype gap+12
Incentives68
Confidence55
invest15 publishers

Most of Bitget's $387.5 million hack loss sits untouched in attacker wallets

Bitget now puts its September breach at $387.5 million, and AMLBot estimates $343 million of it sat untouched in 13 attacker wallets on Sept. 25. The phased withdrawals due from Sept. 28 are the better guide to whether customer money is safe.

Perspective Coverage

15 publishers
Builder
Builder 25%
Operator
Operator 43%
Investor
Investor 32%

Reality

Evidence66
Adoption
Insufficient
Hype gap+20
Incentives60
Confidence62
product3 publishers

Bitget's own approval process moved out $388 million on spoofed transaction data

Bitget says attackers took over a wallet backend system and fed its authorization process spoofed data, moving out $387.5 million without stolen keys. For teams running payouts, the data an approver trusts now belongs on the same review list as the keys.

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 40%
Investor
Investor 37%

Reality

Evidence58
Adoption
Insufficient
Hype gap+18
Incentives62
Confidence60
security4 publishers

Dream Job now ships a kernel exploit: Lazarus pairs recruiter lures with a fresh AFD zero-day

Check Point says the Operation Dream Job chain now escalates through CVE-2026-68820 to install FudModule v3.1. CISA has told federal agencies to patch by August 25.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 61%
Investor
Investor 5%

Reality

Evidence70
Adoption
Insufficient
Hype gap+15
Incentives50
Confidence72
invest3 publishers

Harmony's answer to a forged 4 billion ONE: delete 109,441 confirmed transactions

The layer-1 will rewind both shards to an Aug. 11 checkpoint and ship a client that rejects the exploit's blocks. Finality on Harmony is now whatever the team decides to keep.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 35%
Investor
Investor 32%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives60
Confidence55
security6 publishers

DOJ extradites a Russian accused of pushing macro malware through 255 fake marketplace accounts

A Northern California freelance marketplace's own messaging system carried Excel macro lures to 80,000 of its users across 18 months. Microsoft closed that delivery step in 2022. The same platform lure now shows up in North Korean operations.

Perspective Coverage

6 publishers
Builder
Builder 17%
Operator
Operator 78%
Investor
Investor 5%

Reality

Evidence70
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence68
security5 publishers

DPRK operators compiled their backdoor into the victim's own HAProxy build

Rapid7 says the ted backdoor is built into the victim's existing HAProxy 2.8.12 and hooks its filter API, so the load balancer keeps balancing normally while it logs cookies and injects scripts for selected clients.

Perspective Coverage

5 publishers
Builder
Builder 42%
Operator
Operator 53%
Investor
Investor 5%

Reality

Evidence70
Adoption10
Hype gap+20
Incentives35
Confidence66
invest3 publishers

Harmony offers validators nine times its DeFi TVL to switch off its own chain

Harmony blames state actors and AI agents for shutting the layer-1 it launched in 2019, and the money set aside to pay validators to power down is worth more than everything left locked on the chain it closes.

Perspective Coverage

3 publishers
Builder
Builder 30%
Operator
Operator 38%
Investor
Investor 32%

Reality

Evidence55
Adoption20
Hype gap+45
Incentives75
Confidence60

Earlier coverage

  1. Sekoia and Kudelski split the Lazarus umbrella into six DPRK sub-clusters

    Security · September 9, 2026 · 1 publisher

  2. Arkham traces $30M of North Korean bitcoin through the exchange Washington wants inside its perimeter

    Invest · September 1, 2026 · 1 publisher

  3. Esper recasts the CLARITY Act as sanctions enforcement ahead of a September 15 cloture vote

    Invest · August 27, 2026 · 1 publisher

  4. China's $1 Trillion Illicit Economy Runs On Rails Your Supply Chain Already Uses

    Leadership · August 20, 2026 · 1 publisher

  5. Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel

    Security · August 15, 2026 · 2 publishers

  6. Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held

    Security · August 15, 2026 · 6 publishers