North Korea-linked Lazarus Group and its financially motivated subgroup Bluenoroff/APT38 have been tied to long-running intrusions against banks, SWIFT-connected environments, cryptocurrency businesses, casinos, and other financial targets worldwide. Reporting from multiple investigations links the actors to operations including the Bangladesh Bank theft, compromises at Bancomext and Banco de Chile, and intrusions at banks in Southeast Asia and Europe. Investigators found that the group maintained access for months, compromised SWIFT Alliance infrastructure, patched SWIFT-related components to suppress integrity checks, harvested transaction data, and used keylogging, lateral movement, and anti-forensic measures to conceal activity and disrupt investigations.
Researchers also documented recurring Lazarus tradecraft across these campaigns, including spear phishing, watering-hole attacks, brute force, exploitation of web and client vulnerabilities, fake-TLS command-and-control, service-based persistence, and reuse of malware families and tooling. Technical reporting connected incidents through shared backdoor design, tunneling tools, SWIFT-focused modules, and malware such as SQCSVC and SWPSVC, while newer infrastructure hunting identified phishing domains, linked IP space, and a macOS sample named localfile~.x64 communicating with 104.168.136.24. The combined findings reinforce attribution of these financially driven operations to the Lazarus ecosystem and show an adaptive capability spanning traditional banking networks and digital-asset platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
21 events from the most recent confirmed update back to the earliest known activity.
In a 2025 investigation, DarkAtlas pivoted from IP address 104.168.151.116 and identified additional IPs and phishing domains with similar structural patterns and shared HTTP response characteristics. The report also linked the macOS malware sample localfile~.x64, classified as Cosmic Rust, to APT38/Bluenoroff and said it communicated with C2 server 104.168.136.24.
Lexfo reports that Lazarus and TA505 showed overlap in 2019, including co-located indicators and similar PowerShell post-intrusion scripts used in bank intrusions. The report suggests TA505 may have sold access to compromised bank networks to Lazarus.
Lexfo says it investigated a late-2018 intrusion involving Lazarus malware including SQCSVC and SWPSVC. During incident response, it decrypted command traffic, recovered plugins such as an injector and keylogger, and attributed the intrusion to Lazarus based on malware traits, infrastructure, and compilation patterns.
DarkAtlas states that APT38 compromised Bancomext and Banco de Chile in 2018. The incidents are cited as examples of the subgroup's continued targeting of financial institutions.
In December 2017, Proofpoint reported Lazarus campaigns using cryptocurrency-themed lures to infect victims with PowerRatankba and follow-on malware such as Gh0st RAT to steal credentials for cryptocurrency wallets and exchanges. The report also introduced RatankbaPOS, describing it as a nation-state-linked point-of-sale malware threat targeting South Korean devices for payment-card theft.
Lexfo reports that Lazarus developed mobile malware in 2017 by adding malicious code to a legitimate Android APK distributed outside Google Play. This marked an expansion of Lazarus tooling into mobile platforms.
Kaspersky says attackers used a watering-hole attack via the compromised Polish Financial Supervision Authority website in early 2017, exploiting Adobe Flash Player and Microsoft Silverlight vulnerabilities to deploy Bluenoroff malware into European banks. Lexfo separately reports that more than twenty Polish banks were infiltrated in early 2017 through watering holes exploiting Silverlight vulnerability CVE-2016-0034.
Kaspersky reports that a packed version of a Lazarus-linked backdoor was uploaded from Poland and South Korea in November 2016. The company assessed this sample as a precursor to later attacks on Poland and other European countries.
Kaspersky says Incident #1 occurred at a bank in a Southeast Asian country in August 2016. Attackers compromised the SWIFT Alliance server, deployed Lazarus-linked malware, patched SWIFT-related components to disable integrity checks, and maintained access for more than seven months.
On 2016-05-13, BAE Systems published analysis of the msoutc.exe sample and said code overlaps tied malware used in SWIFT-related bank intrusions, including Bangladesh and a Vietnam bank case, to the earlier destructive malware toolkit associated with the 2014 Sony-era activity. The report cited shared wipe-and-delete functions, similar mutex naming, and the same log-encryption key, while stopping short of definitive attribution.
On 2016-04-25, BAE Systems published technical analysis of malware linked to the February 2016 Bangladesh Bank heist. The report described bespoke tooling that patched SWIFT Alliance Access components, executed Oracle SQL with sysdba privileges, deleted transaction records, altered balances, and manipulated printed confirmations to conceal fraudulent transfers.
Lexfo states that Lazarus was publicly identified and named in Novetta's Operation Blockbuster report in 2016. This marked a major public attribution milestone for the group.
Lexfo states that after late 2016, the Lazarus subgroup Andariel shifted from defense and intelligence targets toward gambling, ATM, financial industry, and cryptocurrency targets. The report frames this as part of a broader move toward revenue-generating operations.
The references describe the 2016 Bangladesh Bank theft as a major Lazarus/APT38 operation, with DarkAtlas stating that $81 million was stolen. Kaspersky says attribution had been debated but confirms Lazarus malware was used in the Bangladesh case.
Lexfo reports that Lazarus targeted ATM operator VANXATM in February 2015, compromising more than 60 ATMs and exfiltrating about 230,000 unique credit card numbers. The incident is presented as an early financially motivated operation.
DarkAtlas states that APT38, also known as Bluenoroff, emerged around 2014 as a financially motivated North Korean subgroup. The reporting describes it as focused on banks, SWIFT environments, ATMs, casinos, and cryptocurrency targets.
Kaspersky and DarkAtlas both cite the 2014 Sony Pictures Entertainment attack as a key Lazarus-linked operation. The references use it as a major historical anchor for Lazarus attribution.
Kaspersky links Lazarus malware to Operation Troy in 2013 and Operation DarkSeoul in 2013, connecting those campaigns to the broader Lazarus activity set. These incidents are cited as major early operations associated with the group.
The Lexfo white paper traces Lazarus operations back to a 2007 DDoS campaign against South Korean and U.S. websites using the MyDoom botnet. It presents this as the earliest known activity in the Lazarus ecosystem.
Lexfo attributes the theft of about $534 million from Coincheck to Lazarus. The report cites the incident as part of the group's focus on cryptocurrency businesses, especially South Korean exchanges.
Lexfo lists WannaCry, FASTCash, GoldDragon, and AppleJeus among major Lazarus-linked operations. The reference presents these campaigns as part of the group's expanding global activity across destructive, financial, and cryptocurrency-focused operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
darkatlas.io
Open sourceproofpoint.com
Open sourceus-cert.gov
Open sourcekaspersky.com
Open sourcebaesystemsai.blogspot.com
Open sourcebaesystemsai.blogspot.com
Open sourceblog.lexfo.fr
Open sourcemedia.kasperskycontenthub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.