Who documents this group
The group known as Lazarus (one of its subgroups is identified as "TraderTraitor") is jointly tracked by several US agencies and security firms, with named, dated public advisories — not rumors.
The method: infiltrate, not just hack
What sets this arm of the group apart is that it doesn't just attack from the outside: operators get hired as real employees or contractors — fake resumes, fake identities, successfully passed interviews — to gain legitimate access to the company's systems. Once inside, they can siphon funds, steal intellectual property, or install malicious tools.
Why this case matters, even without a direct link to your inbox
Most scams an individual receives have no direct link to this particular group. But this case illustrates how structured organized fraud has become: no longer isolated individuals, but networks with documented methods that later spread into more common scams — fake recruiters, social engineering, fake profiles.
Frequently asked questions
Who documents the Lazarus group's activities?
Named public and private bodies: the FBI, CISA and the US Treasury (joint advisory), the US Department of Justice (seizures), plus Microsoft and Google Threat Intelligence / Mandiant on the company-infiltration side.
How does this group get into real companies?
By posing as remote developers or freelance contractors, with fake profiles and fake identities, to gain legitimate access to the hiring company's systems.
What's the link to the scams an individual receives?
No direct link for most victims of ordinary cold-calling or phishing — but this case illustrates just how structured organized fraud has become as an industry, with techniques (social engineering, fake profiles) that later filter down into more common scams.
Other markets we cover
The FBI, CISA and the US Treasury lead the public record on Lazarus, but the group's reach — and the sanctions responding to it — extend well beyond the US.
🇦🇺Australia — sanctions over $1.9 billion in stolen crypto
Australia's Minister for Foreign Affairs sanctioned four North Korean state-linked hacking units — Lazarus Group, Kimsuky, Andariel and Chosun Expo — citing roughly $1.9 billion in cryptocurrency theft used to fund Pyongyang's weapons programs.
Cryptonews, "Australia Impose Sanctions on North Korean Lazarus Over $1.9B Crypto Theft."🇬🇧United Kingdom — NCSC backed criminal charges against Lazarus operators
The UK attributed the 2017 WannaCry ransomware outbreak to Lazarus Group in December 2017, alongside the US, Australia, Canada, New Zealand and Japan, and sanctioned the linked entity Chosun Expo under its autonomous cyber sanctions regime. The National Cyber Security Centre also publicly backed the US Department of Justice's criminal charges against three North Korean hackers tied to the group.
National Cyber Security Centre (NCSC.GOV.UK), "UK supports US charges against North Korean cyber actors."🇨🇦Canada — RCMP advisory on North Korean IT-worker infiltration
In July 2025, the RCMP, Public Safety Canada, Global Affairs Canada, FINTRAC and the Canadian Centre for Cyber Security issued a joint advisory warning employers about North Korean state-linked IT workers using fake or stolen identities to land remote jobs — the same infiltration tactic this page describes. A Canadian national, Ghaleb Alaumary of Mississauga, Ontario, was separately charged by US federal prosecutors for laundering funds tied to the same North Korean network.
Royal Canadian Mounted Police, "Advisory on North Korean information technology (IT) workers," July 2025.🇮🇳India — the WazirX exchange breach, roughly $235 million
Indian crypto exchange WazirX lost approximately $234.9 million in a multi-signature wallet breach reported in July 2024, attributed by blockchain-analysis firms and media reporting to the Lazarus Group. It stands among the group's largest confirmed exchange heists outside the US and South Korea.
The Record (Recorded Future News), "Officials accuse North Korea's Lazarus of theft from crypto exchange."Go further
Egidio — The Threat Laboratory, "Documented criminal networks: the Lazarus case", egidio.app/en/laboratoire/lazarus-criminal-network/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.