North Korea's nuclear weapons are not funded by traditional revenue sources like coal or taxes, but are supported by stolen cryptocurrency. On July 18, 2024, North Korea's top hacking group, Lazarus Group, launched a bold attack on WazirX, India's largest cryptocurrency exchange.

In just over an hour, the group stole more than $200 million and vanished before any response could catch up. The attack was organized like a professional military campaign. The heist at WazirX was just one of many activities directly linked to Lazarus.

Over the past 10 years, Lazarus has stolen more than $6 billion, making the group the most dangerous cryptocurrency thief in the world. According to a report from the Wall Street Journal, Lazarus's activities play a crucial role in sustaining Kim Jong Un's regime while funding the nuclear program despite stringent international sanctions.

Lazarus: A gathering of the brightest minds in North Korea

Benedict Hamilton, CEO at Kroll – the company assisting WazirX in tracking the theft, noted that the speed and level of automation of the group suggest that the stolen money may have been converted into cash immediately after the attack.

With nearly half of its assets lost, WazirX was forced to suspend operations. A spokesperson for the exchange stated that they are striving to recover user funds and expect to resume operations soon.

Lazarus is formed from the brightest minds in North Korea, and the group is not hasty in its campaigns. They spend months, even years, researching targets, creating fake profiles, and seeking a single weakness to exploit.

To infiltrate company systems, Lazarus uses personal information from employees' Instagram, LinkedIn, and Facebook accounts, then builds personalized phishing schemes to lure them into clicking on links containing malware.

Some Lazarus members even applied for remote jobs at U.S. tech companies using fake identities, passing interviews and working inside the system to access data. These campaigns are organized and operated like professional military campaigns, with state backing.

North Korea and the cryptocurrency theft strategy

In February 2024, Lazarus executed the largest theft in the group's history – stealing $1.5 billion from Bybit, one of the largest cryptocurrency exchanges in the world. According to reports from Chainalysis, in 2024 alone, North Korea accounted for over 60% of the total money stolen across the entire cryptocurrency sector.

The country has built a formidable cyber army with more than 8,000 hackers working full-time, organized into teams modeled after the military and supported by many smaller departments, according to the Wall Street Journal.

Children with talents in mathematics or science are selected early and trained intensively to become hackers. They do not have side jobs, dedicating all their time to cyber attack activities.

Though living better than most North Korean citizens, these hackers face immense pressure and risk severe punishment if they fail. Elma Duval, co-author of a report from the Seoul-based advocacy group PScore, interviewed former IT employees and revealed that hackers are often physically punished if they do not complete their tasks.

Kim Jong Il, the late leader of North Korea, once stated that future wars would be conducted by computers. This vision has become a national strategy under Kim Jong Un.

With traditional revenue sources such as arms trading, coal smuggling, and foreign labor choked by international sanctions, North Korea has been forced to seek new sources of income. The country's intelligence agency estimates that North Korea needs about $6 billion a year, including hundreds of millions of dollars to maintain its nuclear weapons program.

Cryptocurrency has become the ideal choice: fast, low-cost, and hard to trace. Although North Korea has never publicly claimed responsibility for any attacks, U.S. officials say Lazarus often leaves traces, including malware and wallets that have been reused from previous hacks.

The group has been accused of involvement in major attacks such as the 2014 Sony hack, the 2016 Bangladesh central bank heist, and the 2017 WannaCry ransomware attack.

Lazarus: The new target is cryptocurrency ETF funds and job candidates

In September 2024, the FBI issued a warning that Lazarus was targeting companies related to ETF funds. This is an attractive segment of the market with $37 billion in investment inflows last year, including funds from BlackRock, Fidelity, and many other major companies. Lazarus has used emails containing malware specifically designed to target each victim.

In December 2024, a U.S. court indicted 14 North Koreans for stealing the identities of Americans and applying for jobs at U.S. tech companies and non-profit organizations. These Lazarus members refer to themselves as 'IT warriors,' earning $88 million in salaries, all of which was sent directly back to North Korea.

These jobs give them direct access to the company’s systems and data. Some cryptocurrency companies have confirmed being attacked by fake applicants.

Ben Turner, head of engineering at Cloudburst Technologies – a cryptocurrency intelligence company, stated: 'We are increasingly aware of the presence of North Korean hackers around us.' His team has also noted a significant increase in suspicious job applications, indicating that Lazarus is expanding its operations.

Disclaimer: This article is for informational purposes only, not investment advice. Investors should do thorough research before making decisions. We are not responsible for your investment decisions.

$BTC

BTC
BTC
84,262.01
-0.10%

$ETH

ETH
ETH
2,679.28
-0.53%

$BNB

BNB
BNB
775.68
+0.31%