Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Lazarus Group Launders Crypto via Mixers, Deploys New Malware Targeting Developers

Lazarus Group Launders Crypto via Mixers, Deploys New Malware Targeting Developers

DeFi PlanetDeFi Planet2025/03/14 11:06
By:DeFi Planet

North Korean-affiliated hacking group Lazarus has continued its illicit activities, moving stolen crypto through mixers and launching new malware attacks on developers.

North Korean-affiliated hacking group Lazarus has continued its illicit activities, moving stolen crypto through mixers and launching new malware attacks on developers.

On March 13, blockchain security firm CertiK flagged a 400 ETH deposit valued at approximately $750,000 into the Tornado Cash mixing service. According to CertiK, the funds originated from Lazarus’ activities on the Bitcoin network.

“The fund traces to the Lazarus group’s activity on the Bitcoin network,” 

CertiK noted

Lazarus has been linked to several major crypto exchange breaches, including the Bybit hack on February 21, where $1.4 billion was stolen. The group was also behind the $29 million Phemex exploit in January and has been laundering stolen assets ever since. Notably, Lazarus was responsible for some of the largest crypto hacks in history, including the $600 million Ronin bridge attack in 2022.

Data from Chainalysis reveals that in 2023, North Korea-affiliated hackers stole approximately $660.50 million across 20 incidents; in 2024, this number increased to $1.34 billion stolen across 47 incidents — a 102.88% increase in value stolen. These figures represented 61% of the total amount stolen for the year and 20% of total incidents.

Similarly, cybersecurity researchers at Socket uncovered six new malicious packages deployed by Lazarus to compromise developer environments. These packages, embedded in the Node Package Manager (NPM) ecosystem, are designed to steal credentials, extract cryptocurrency-related data, and install backdoors.

Notably, Researchers identified a malware strain called “BeaverTail,” which uses typosquatting tactics—mimicking legitimate JavaScript libraries with slightly altered names to deceive developers into installing them. The malware is hazardous as it targets cryptocurrency wallets, including Solana and Exodus, and harvests sensitive data from browsers such as Google Chrome, Brave, and Firefox. On macOS, it goes further, attempting to access keychain data to compromise stored credentials. While definitive attribution remains challenging, researchers emphasized that the tactics, techniques, and procedures (TTPs) closely align with Lazarus’ known operations.

 

If you want to read more news articles like this, visit DeFi Planet and follow us on Twitter , LinkedIn , Facebook , Instagram , and CoinMarketCap Community.

“Take control of your crypto portfolio with MARKETS PRO, DeFi Planet’s suite of analytics tools.”

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!