OAK — OnChain Attack Knowledge

Threat actor · OAK-G01

OAK-G01 — Lazarus Group / DPRK-attributed crypto theft

Aliases
APT38, BlueNoroff, Hidden Cobra, Andariel, "TraderTraitor" (FBI naming for DPRK crypto-theft cluster).
First observed in crypto
approximately 2017 (Sony Pictures intrusions and SWIFT-targeting predate; crypto pivot consolidated 2017–2018).
Attribution status
confirmed by FBI public statements, U.S. Treasury OFAC designations, U.S. Department of Justice indictments, and multiple national CERT bodies (KISA, NCSC, BSI). Attribution to the Reconnaissance General Bureau of the DPRK is the standing public position of the U.S. government.
Active
yes (as of v0.1).

Description

Lazarus Group is the public umbrella label for state-aligned cyber-theft activity attributed to the Democratic People's Republic of Korea, with crypto-asset theft now its dominant revenue-generating activity. Per [chainalysis2024dprk], North Korean actors stole approximately $1.34B across 47 incidents in 2024 (61% of all attacker-stolen value globally that year), with the 2025 figure reported at approximately $2.02B (a 51% year-on-year increase) and all-time totals exceeding $6.75B. The single largest attributed event to date is the Bybit exchange theft of February 21, 2025 (~$1.46–$1.5B in ETH equivalent).

Operationally, Lazarus's modern crypto-theft playbook combines social engineering (notably LinkedIn-delivered fake-job-offer phishing payloads against engineering staff at exchanges, bridge operators, and infrastructure vendors), software-supply-chain compromise of third-party tooling (the Bybit case implicated a multisig-platform vendor's developer workstation), private-key extraction from validator and signing infrastructure, and laundering through mixers and cross-chain bridges ([ofac2022tornado] is part of this story; post-2022 laundering routes have shifted across services as enforcement landed). FBI's "TraderTraitor" naming captures the social-engineering-led intrusion vector that connects most modern incidents.

Targeting profile

  • Centralised exchanges: Bybit (Feb 2025), WazirX (Jul 2024), Atomic Wallet (Jun 2023), Stake.com (Sep 2023), KuCoin (2020), and many others.
  • Cross-chain bridges: Ronin (Mar 2022), Harmony Horizon (Jun 2022).
  • Individual high-balance wallets: small-N but high-value, typically follow-on after broader infrastructure compromise.
  • Infrastructure vendors and DeFi tooling: supply-chain compromise as a force multiplier (e.g., Safe{Wallet} workstation compromise per the Bybit case).

Observed Techniques

  • OAK-T7.001 (Mixer-Routed Hop) — extensive Tornado Cash usage through 2022; post-2022 shift to alternate mixers as a partial / earlier-stage component of the broader laundering chain.
  • OAK-T7.003 (Cross-Chain Bridge Laundering) — the dominant post-2022 Lazarus laundering rail. Per [chainalysisbybitthorchain] (Chainalysis's primary attribution for the operator-fee figure, wrapped by [coindeskthorchainlazarus2025] for narrative reporting) and [chainalysis2024laundering], the OAK-G01 Lazarus Group laundered the full ~$1.4B of Bybit-extracted ETH through THORChain in approximately 10 days post-extraction (THORChain node operators collectively earned at least ~$12M in fees from the operation; figure is verified-with-caveat at v0.1 — single primary source for the precise dollar amount).
  • OAK-T7.006 (DeFi Yield-Strategy Laundering) — post-Tornado-Cash-sanctions shift from mixer services to DeFi yield protocols (Aave, Compound, Lido, Yearn, Convex) as "yield user" cover for laundering; documented by Chainalysis [chainalysis2024laundering] as the structural laundering-infrastructure shift across 2023–2025; G01 is the highest-volume documented cluster using this technique at scale.
  • OAK-T7.002 (CEX Deposit-Address Layering) — downstream off-ramp Technique; per-cluster aggregate inflow tracking against OAK-G01 watchlists is the canonical compliance-side detection.
  • OAK-T8.001 (Common-Funder Cluster Reuse) — sustained operator continuity is a defining feature; Lazarus wallet clusters are tracked across incidents by major industry forensics providers.
  • OAK-T10.001 (Validator / Signer Key Compromise) — the canonical Lazarus bridge-targeting Technique. Ronin (March 2022) and Harmony Horizon (June 2022) are both T10.001 + G01 cases.
  • OAK-T11.001 (Third-Party Signing/Custody Vendor Compromise) — the canonical Lazarus exchange/custody-targeting Technique post-2023. Bybit (Feb 2025), WazirX (July 2024). Atomic Wallet (June 2023) is the related T11.002 case.
  • OAK-T11.002 (Wallet-Software Distribution Compromise) — Atomic Wallet (June 2023) canonical case targeting end-user self-custodial wallets at scale.
  • OAK-T11.003 (In-Use Multisig Smart-Contract Manipulation) — WazirX (July 2024) canonical case (chained from T11.001 entry vector).
  • OAK-T9.004 (Access-Control Misconfiguration) — the Wormhole bridge incident is not Lazarus-attributed and is a separate operator's activity, but the bridge-class targeting profile overlaps with cases that are Lazarus-attributed.
  • Pre-incident vectors not yet in OAK: social-engineering as an off-chain entry vector (LinkedIn fake-job-offer payload delivery; supply-chain compromise of vendor developer workstations). These are out of scope for OAK's on-chain Tactic taxonomy but are documented here because they are the dominant Lazarus entry vector in 2022-2025.

Observed Examples

Citations

  • [chainalysis2024dprk] — DPRK-attributed scale (2024 $1.34B / 47 incidents; 2025 $2.02B; cumulative >$6.75B per Chainalysis).
  • [ellipticronin2022] — Ronin Bridge forensic write-up, FBI / Treasury attribution.
  • [ofac2022tornado] — Tornado Cash designation cites Lazarus-attributed laundering volume as part of the legal basis.
  • (Bybit-specific citations live in the Bybit worked example.)

Discussion

Lazarus's attribution evolution over 2017–2025 is a case study in itself. Early activity (2017–2019) was attributed primarily through malware-fingerprint and infrastructure-reuse analysis; the wallet-cluster forensics layer became a major attribution surface from 2020 onward as Chainalysis, Elliptic, and TRM Labs published cluster analyses with FBI-corroborated attribution. The 2025 Bybit case combined off-chain (social-engineering, supply-chain compromise) and on-chain (wallet-cluster, bridge-and-mix laundering pattern) attribution surfaces to produce one of the fastest public attributions in industry history (FBI IC3 PSA published within five days of the event).

For OAK contributors writing future Lazarus-attributed examples: preserve the distinction between confirmed attribution (FBI / Treasury / DOJ public statements) and inferred-strong attribution (industry-forensic-only). The Bybit and Ronin cases are confirmed; many smaller incidents in the cohort are inferred-strong only and should be marked as such in the example header.

Software used