Lazarus Group operates under North Korea's Reconnaissance General Bureau and is unique among state actors in that revenue generation is a core, sanctioned mission rather than a sideline.
The scale is difficult to overstate. UN Panel of Experts reporting has assessed that DPRK cyber operations have generated billions of dollars, with a substantial share directed to the country's weapons programmes. In February 2025 the group stole approximately $1.5 billion in cryptocurrency from the Bybit exchange — the largest theft, by value, ever recorded by any method.
Its history spans the full range of state cyber activity. The 2014 destruction of Sony Pictures Entertainment's network, in retaliation for a film depicting Kim Jong Un's assassination, combined data theft, public leaking, and disk wiping. The 2016 Bangladesh Bank operation abused SWIFT credentials to attempt $951 million in fraudulent transfers, succeeding with $81 million before a spelling error in one instruction — "fandation" for "foundation" — triggered a manual review. WannaCry in May 2017 spread through EternalBlue to over 200,000 machines in 150 countries, disabling substantial parts of the UK's National Health Service.
Its most refined technique is patient social engineering of individual engineers. Operation Dream Job and its successors approach developers at cryptocurrency and defence firms with fabricated recruitment offers, conduct multi-round interviews, and deliver malware inside a "coding assessment" the candidate is asked to run. In the 2023 JumpCloud and 3CX incidents this produced cascading supply-chain compromise — 3CX being the first publicly documented instance of one software supply-chain attack being used to stage another.
The DPRK also runs a parallel programme placing IT workers in remote roles at Western companies under false identities, generating salary revenue and, in some cases, insider access.