Lazarus Group (TraderTraitor / APT38 / UNC4736)
North Korean state-sponsored (RGB — Lazarus sub-cluster) · Financial theft / cryptocurrency theft / sanctions evasion
Tactics, Techniques & Procedures (TTPs)
- TraderTraitor: LinkedIn and Telegram fake job offer social engineering targeting developers at crypto exchanges
- Trojanised developer tools, malicious npm and PyPI packages for supply chain compromise
- Safe{Wallet} developer device compromise to inject malicious JavaScript into multisig wallet interface (Bybit, Feb 2025)
- AppleJeus macOS malware family for cryptocurrency platform targeting
- GitHub repository social engineering and fake open-source project contributions
- SWIFT financial messaging system compromise (APT38 historical, BankBotABE/DYEPACK malware)
Known Targets
Analyst Notes
This tracking cluster combines overlapping Lazarus sub-designations: APT38 (financial crime wing focused on SWIFT and banking); UNC4736/TraderTraitor (developer supply chain and cryptocurrency theft). The February 2025 Bybit theft — $1.5 billion, the largest single cryptocurrency theft on record — was executed via compromise of a Safe{Wallet} developer machine, injecting malicious JavaScript into the multisig wallet interface that transparently substituted attacker-controlled addresses during signing. The attack required no access to Bybit systems directly. Estimated $3B+ stolen in cryptocurrency since 2017; proceeds fund North Korean weapons programmes. See also: Lazarus Group (parent cluster profile).
Also Known As