The U.S. Department of Justice unsealed charges against three alleged North Korean military hackers tied to the Reconnaissance General Bureau, identifying them as members of the Lazarus Group/APT38 behind a years-long campaign of cyberattacks and financial crime. Prosecutors linked the defendants to the 2014 Sony Pictures intrusion, SWIFT-enabled bank theft attempts including the Bangladesh Bank case, FASTCash ATM cash-out operations, the WannaCry 2.0 ransomware outbreak, spear-phishing, and the AppleJeus cryptocurrency malware scheme. Authorities said the operations targeted banks, cryptocurrency businesses, and other organizations worldwide, with attempted thefts and losses totaling roughly $1.3 billion.
Security and law-enforcement reporting described a broad Lazarus toolkit used across those operations, including malware such as Trojan.Banswift, Backdoor.Contopee, Downloader.Ratankba, Trojan.Fastcash, and AppleJeus variants, while WannaCry was noted to have spread via EternalBlue against Windows flaws including CVE-2017-0144 and CVE-2017-0145. The case also connected North Korean operators to laundering networks and later cryptocurrency theft activity, including the FBI’s attribution of the $100 million Harmony Horizon Bridge theft to Lazarus and its TraderTraitor campaign. U.S. authorities said they seized about $1.9 million in stolen cryptocurrency, issued victim notifications and joint guidance, and continued efforts to trace and freeze assets used to fund Pyongyang’s weapons programs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
34 events from the most recent confirmed update back to the earliest known activity.
The FBI confirmed that Lazarus Group, also known as APT38, was responsible for the $100 million theft from Harmony's Horizon Bridge and linked the intrusion to the TraderTraitor malware campaign.
The FBI said DPRK-linked actors used the RAILGUN privacy protocol to launder more than $60 million worth of stolen Ethereum from the Harmony heist, with some funds sent to service providers and converted into Bitcoin.
The FBI said the theft of $100 million in virtual currency from Harmony's Horizon Bridge was reported on June 24, 2022.
The FBI obtained seizure warrants for cryptocurrency held at two exchanges and seized about $1.9 million for return to the New York financial services victim.
The FBI, CISA, and the Treasury Department released a joint advisory and malware analysis reports identifying malware and indicators of compromise associated with the AppleJeus family of North Korean cryptocurrency applications.
Federal prosecutors also unsealed a charge against Ghaleb Alaumary, who agreed to plead guilty to conspiracy to commit money laundering tied to ATM cash-outs, bank heists, and other cybercrime schemes linked to North Korea.
The U.S. Department of Justice unsealed an indictment charging Jon Chang Hyok, Kim Il, and Park Jin Hyok over a broad conspiracy involving cyberattacks, bank thefts, ransomware, cryptocurrency theft, and fraudulent blockchain ventures.
The DOJ indictment alleges the malicious cryptocurrency application campaign continued through at least September 2020 and included apps such as Celas Trade Pro, Union Crypto Trader, Kupay Wallet, CoinGo Trade, Dorusio, CryptoNeuro Trader, and Ants2Whale.
The DOJ indictment alleges the conspirators stole $11.8 million from a New York financial services company using the malicious CryptoNeuro Trader application as a backdoor.
The DOJ indictment alleges the conspirators extorted and attempted to extort victim companies from 2017 through 2020 using data theft and ransomware deployment.
The DOJ says Ghaleb Alaumary conspired with Ramon Olorunwa Abbas and others to launder funds from a North Korean cyber-enabled heist against a Maltese bank.
The DOJ indictment frames the fraudulent SWIFT-message bank theft attempts as running through 2019 across victims in Vietnam, Bangladesh, Taiwan, Mexico, Malta, and Africa.
Check Point reported a likely Lazarus campaign using malicious Office documents and an updated KEYMARBLE backdoor against Russian-based companies.
The DOJ indictment alleges the conspirators stole $6.1 million from BankIslami Pakistan Limited in a FASTCash ATM cash-out operation.
The DOJ states that Park Jin Hyok had previously been charged in a criminal complaint that was unsealed in September 2018.
The DOJ indictment alleges the conspirators stole $24.9 million from an Indonesian cryptocurrency company.
The DOJ indictment alleges the conspirators developed malicious cryptocurrency applications from March 2018 through at least September 2020 to gain backdoor access to victims' computers and steal cryptocurrency.
Symantec reported that in 2018 Lazarus was tied to FASTCash attacks in Africa and Asia, in which malware on ATM switch servers falsified approval responses for fraudulent withdrawals.
Proofpoint reported multistage Lazarus campaigns using cryptocurrency-themed lures, new PowerRatankba malware, and follow-on credential theft targeting wallets and exchanges.
The DOJ indictment alleges the conspirators stole $75 million from a Slovenian cryptocurrency company.
The DOJ indictment alleges the conspirators created WannaCry 2.0 in May 2017, and Symantec says the ransomware infected hundreds of thousands of computers worldwide within hours.
The DOJ indictment alleges the conspirators developed and marketed the Marine Chain Token in 2017 and 2018 to obtain investor funds, gain interests in shipping vessels, and evade U.S. sanctions.
Symantec reported that in 2017 dozens of organizations, mostly banks, were targeted in watering-hole attacks using a custom exploit kit and the Downloader.Ratankba malware.
The DOJ indictment alleges the conspirators ran spear-phishing campaigns from March 2016 through February 2020 against U.S. defense contractors, energy and aerospace firms, technology companies, and U.S. government departments.
Symantec and Proofpoint both link Lazarus to the 2016 Bangladesh Central Bank attack, in which $81 million was stolen.
The DOJ indictment alleges the conspirators attempted from 2015 through 2019 to steal more than $1.2 billion from banks in multiple countries using fraudulent SWIFT messages.
The DOJ indictment alleges the conspirators intruded into Mammoth Screen while it was producing a fictional television series involving North Korea.
The DOJ indictment alleges the conspirators targeted AMC Theatres because it was scheduled to show "The Interview."
The DOJ indictment alleges the North Korean conspirators carried out the destructive cyberattack on Sony Pictures Entertainment in retaliation for the film "The Interview."
Proofpoint noted that the March 20, 2013 attack in South Korea has been attributed to the Lazarus Group, marking an early publicly referenced operation tied to the actor.
The FBI published a February 6 update listing North Korean-controlled virtual currency wallets that had contained or continued to contain stolen Harmony assets.
SentinelOne summarized a US-CERT release of malware analysis reports on Lazarus-linked families including BISTROMATH, HOPLIGHT, SLICKSHOES, CROWDEDFLOUNDER, HOTCROISSANT, ARTFULPIE, and BUFFETLINE.
Symantec reported that a security researcher registered WannaCry's non-existent kill-switch domain, limiting the malware's spread.
Symantec reported that banking attacks linked to Lazarus prompted an alert by SWIFT after attackers used malware to hide evidence of fraudulent transfers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
rusi.org
Open sourcecve.mitre.org
Open sourcefbi.gov
Open sourcelabs.sentinelone.com
Open sourceresearch.checkpoint.com
Open sourceproofpoint.com
Open sourcecommunity.broadcom.com
Open sourcecve.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.