Egidio
Report · 2026

Documented criminal networks: the Lazarus case

Not every fraud is a small operation — some are run by structured groups, named and documented by federal agencies and security firms. Here's one particularly well-tracked case.

Protect my phone with Egidio Free for calls · 100% on your phone · no account needed

Who documents this group

The group known as Lazarus (one of its subgroups is identified as "TraderTraitor") is jointly tracked by several US agencies and security firms, with named, dated public advisories — not rumors.

April 2022
Joint advisory from the FBI, CISA (the US cybersecurity agency) and the US Treasury, attributing TraderTraitor's activity to the Lazarus group.
2023
The US Department of Justice announces the seizure of more than $15 million in crypto assets stolen by the group across four exchanges.
May 2024
Theft of $308 million from the DMM Bitcoin exchange — attributed to TraderTraitor by the FBI and Japan's National Police Agency (NPA).
Late 2024
Theft of $1.5 billion from the Bybit exchange — publicly attributed by the FBI to North Korean TraderTraitor actors.
2025
Microsoft and Google Threat Intelligence / Mandiant document a separate angle: operators posing as fake remote developers or freelance contractors, infiltrating real companies to steal crypto assets or intellectual property.
$1.5B
Theft attributed to the group on the Bybit exchange, late 2024.
FBI, public attribution, late 2024. Accessed 07/14/2026.
$308M
Theft from the DMM Bitcoin exchange, May 2024.
FBI & Japan's National Police Agency (NPA), May 2024. Accessed 07/14/2026.

The method: infiltrate, not just hack

What sets this arm of the group apart is that it doesn't just attack from the outside: operators get hired as real employees or contractors — fake resumes, fake identities, successfully passed interviews — to gain legitimate access to the company's systems. Once inside, they can siphon funds, steal intellectual property, or install malicious tools.

Why this case matters, even without a direct link to your inbox

Most scams an individual receives have no direct link to this particular group. But this case illustrates how structured organized fraud has become: no longer isolated individuals, but networks with documented methods that later spread into more common scams — fake recruiters, social engineering, fake profiles.

🔒 Whether the threat comes from an organized group or a lone scammer, the principle for protecting yourself stays the same: spot the pattern, not just the isolated message. That's exactly what Medusa, Egidio's engine, does. See how it works.

Frequently asked questions

Who documents the Lazarus group's activities?

Named public and private bodies: the FBI, CISA and the US Treasury (joint advisory), the US Department of Justice (seizures), plus Microsoft and Google Threat Intelligence / Mandiant on the company-infiltration side.

How does this group get into real companies?

By posing as remote developers or freelance contractors, with fake profiles and fake identities, to gain legitimate access to the hiring company's systems.

What's the link to the scams an individual receives?

No direct link for most victims of ordinary cold-calling or phishing — but this case illustrates just how structured organized fraud has become as an industry, with techniques (social engineering, fake profiles) that later filter down into more common scams.

Other markets we cover

The FBI, CISA and the US Treasury lead the public record on Lazarus, but the group's reach — and the sanctions responding to it — extend well beyond the US.

🇦🇺Australia — sanctions over $1.9 billion in stolen crypto

Australia's Minister for Foreign Affairs sanctioned four North Korean state-linked hacking units — Lazarus Group, Kimsuky, Andariel and Chosun Expo — citing roughly $1.9 billion in cryptocurrency theft used to fund Pyongyang's weapons programs.

Cryptonews, "Australia Impose Sanctions on North Korean Lazarus Over $1.9B Crypto Theft."

🇬🇧United Kingdom — NCSC backed criminal charges against Lazarus operators

The UK attributed the 2017 WannaCry ransomware outbreak to Lazarus Group in December 2017, alongside the US, Australia, Canada, New Zealand and Japan, and sanctioned the linked entity Chosun Expo under its autonomous cyber sanctions regime. The National Cyber Security Centre also publicly backed the US Department of Justice's criminal charges against three North Korean hackers tied to the group.

National Cyber Security Centre (NCSC.GOV.UK), "UK supports US charges against North Korean cyber actors."

🇨🇦Canada — RCMP advisory on North Korean IT-worker infiltration

In July 2025, the RCMP, Public Safety Canada, Global Affairs Canada, FINTRAC and the Canadian Centre for Cyber Security issued a joint advisory warning employers about North Korean state-linked IT workers using fake or stolen identities to land remote jobs — the same infiltration tactic this page describes. A Canadian national, Ghaleb Alaumary of Mississauga, Ontario, was separately charged by US federal prosecutors for laundering funds tied to the same North Korean network.

Royal Canadian Mounted Police, "Advisory on North Korean information technology (IT) workers," July 2025.

🇮🇳India — the WazirX exchange breach, roughly $235 million

Indian crypto exchange WazirX lost approximately $234.9 million in a multi-signature wallet breach reported in July 2024, attributed by blockchain-analysis firms and media reporting to the Lazarus Group. It stands among the group's largest confirmed exchange heists outside the US and South Korea.

The Record (Recorded Future News), "Officials accuse North Korea's Lazarus of theft from crypto exchange."

Go further

Cite this page Egidio — The Threat Laboratory, "Documented criminal networks: the Lazarus case", egidio.app/en/laboratoire/lazarus-criminal-network/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.