North Korean Lazarus group linked to 31 cyberattacks, suspected in $30.6M Upbit breach

The actual number of attacks could be substantially higher than any public accounting suggests.
AhnLab's assessment acknowledges that sophisticated hacking groups deliberately hide their activity from detection.
Mark

Why does it matter that this is the same group behind the 2019 attack? Couldn't this just be coincidence—similar methods used by different attackers?

Mimi

The similarity matters because it suggests either the group never faced real consequences for the 2019 theft, or they've been operating continuously in the same environment without being stopped. If it's the same playbook six years later, that's a sign the defenses haven't fundamentally changed.

Mark

The report says the actual number of attacks could be higher. How much higher are we talking about?

Mimi

That's the unsettling part—nobody really knows. These groups use encryption, stolen infrastructure, and dormant code. For every attack that gets detected and attributed, there could be five more that go unnoticed or get misattributed to someone else. The 31 is the floor, not the ceiling.

Mark

Why would North Korea specifically target cryptocurrency exchanges? They're not a government institution.

Mimi

Exchanges hold real money and digital assets that can be moved instantly across borders. For a country under sanctions, that's invaluable—it's a way to convert stolen assets into usable currency without going through traditional banking systems. It's also intelligence gathering. Every successful breach teaches them more about how to hit bigger targets.

Mark

Dunamu said it would cover the full loss. Does that mean customers are protected?

Mimi

Technically, yes—Dunamu absorbed it. But that's a 30-million-dollar hit to the company's balance sheet. The real question is whether other exchanges can afford to do the same, and whether this will push them to invest more in security or just accept the risk as a cost of doing business.

Mark

What happens next? Is there a way to actually stop Lazarus?

Mimi

The investigation might yield attribution details or intelligence about their methods. But stopping them requires either disrupting their infrastructure, which is hard when they're state-backed, or raising the cost of operations so high they move elsewhere. Right now, the cost appears to be manageable for them.

  • Lazarus topped global APT rankings with 31 confirmed cyberattacks in a single year, with fellow North Korean group Kimsuky close behind at 27 — together painting a picture of relentless, coordinated state-sponsored aggression.
  • Upbit, South Korea's largest crypto exchange, lost approximately $30.6 million in Solana assets last week in what investigators believe is a deliberate replay of a 2019 Lazarus attack that cost the same platform 58 billion won in Ethereum.
  • Dunamu, Upbit's parent company, has pledged to cover the full loss from its own reserves, a move designed to contain panic — but the breach has already rattled confidence in the security of South Korea's cryptocurrency sector.
  • Security firm AhnLab warns that 31 incidents likely represents only a fraction of Lazarus's true activity, as the group's sophisticated evasion techniques leave vast portions of their operations invisible to even capable defenders.
  • South Korean authorities have launched an on-site investigation at Upbit, seeking to trace how attackers gained access, how long they persisted undetected, and what this means for the country's broader financial infrastructure.

From the shadows of state-sponsored digital warfare, North Korea's Lazarus Group has once again surfaced as the most active advanced persistent threat actor of the past year, linked to at least 31 cyberattacks between October 2024 and September 2025. Their latest suspected operation struck Upbit, South Korea's largest cryptocurrency exchange, draining roughly $30.6 million in Solana assets through methods eerily reminiscent of a 2019 attack on the very same platform. The recurrence speaks to something deeper than opportunism — it reflects a sustained, strategic campaign by a state actor that has learned to treat digital infrastructure as both a treasury and a testing ground. South Korea now faces the familiar challenge of defending an open, innovative economy against an adversary for whom patience and invisibility are primary weapons.

North Korea's Lazarus Group has claimed the top position among the world's most active state-sponsored hacking operations, according to a security assessment released Sunday by Seoul-based AhnLab Inc. Between October 2024 and September 2025, the group was tied to at least 31 separate cyberattacks, with fellow North Korean collective Kimsuky following at 27 incidents — a combined volume that signals sustained, deliberate pressure on targets across the region and beyond.

The report arrived with particular urgency because Lazarus is now the prime suspect in a major breach of Upbit, South Korea's largest cryptocurrency exchange. Last week, unauthorized actors transferred approximately 44.5 billion won — roughly $30.6 million — in Solana-affiliated assets out of the platform's control. Dunamu, the company operating Upbit, announced it would absorb the loss entirely from its own reserves, a gesture aimed at preserving user confidence even as the scale of the theft became clear.

What distinguishes this incident is its apparent continuity with the past. South Korean investigators noted that the methods used in the recent attack closely mirror those deployed in a 2019 Lazarus breach of the same exchange, which yielded 58 billion won in Ethereum. The resemblance suggests not a coincidence but a consistent operational playbook — or worse, a group that has spent years refining the same approach while evading detection and remediation entirely.

AhnLab was careful to note that 31 incidents almost certainly understates Lazarus's true reach. Advanced persistent threat groups are engineered for invisibility — dormant code, encrypted channels, masked origins — meaning many attacks go unreported or undetected. The acknowledgment reflects an honest reckoning with the limits of cybersecurity visibility, even among the most capable defenders.

Authorities have begun an on-site investigation at Upbit, focusing on how attackers gained initial access, what persistence mechanisms they established, and how long they may have operated undetected before executing the theft. The answers carry implications far beyond one exchange — South Korea hosts some of the world's largest crypto platforms, and Lazarus has long demonstrated an ability to treat financial infrastructure as both a source of hard currency and a strategic proving ground. Whether the investigation yields evidence sufficient to disrupt or deter the group remains the defining question in the weeks ahead.

A North Korean hacking group known as Lazarus has emerged as the most prolific advanced persistent threat actor tracked over the past year, according to a security assessment released Sunday by AhnLab Inc., a Seoul-based software security firm. Between October 2024 and September 2025, the group was linked to at least 31 separate cyberattacks—a volume that places it at the top of the rankings for organized state-sponsored hacking operations. A second North Korean-backed group, Kimsuky, followed with 27 confirmed incidents during the same period, underscoring the sustained pressure these adversaries are placing on targets across the region and beyond.

The timing of the report carries particular weight because Lazarus is now the prime suspect in a major cryptocurrency heist that struck South Korea's largest digital asset exchange just days earlier. Last week, Upbit—the platform operated by Dunamu—confirmed that unauthorized actors had transferred approximately 44.5 billion won in Solana-affiliated assets, equivalent to roughly $30.6 million, to wallets outside the company's control. Dunamu announced it would absorb the full loss using its own reserves, a commitment that underscores both the severity of the breach and the exchange's attempt to stabilize confidence among its users.

What makes the Upbit incident particularly significant is not merely its scale but the apparent continuity of method. South Korean authorities noted that the techniques deployed in this latest attack bear striking similarities to a 2019 breach in which Lazarus allegedly stole 58 billion won worth of Ethereum from the same exchange. The parallel suggests either a consistent operational playbook or, more troublingly, that the group has successfully evaded detection and remediation for years while refining the same approach. The resemblance has prompted investigators to treat the recent incident as part of a longer pattern rather than an isolated event.

AhnLab's assessment carries an important caveat: the 31 incidents attributed to Lazarus likely represent only a fraction of the group's actual activity. Advanced persistent threat groups employ sophisticated techniques specifically designed to avoid detection—dormant code, encrypted communications, compromised infrastructure that masks their true origin. Many attacks go unreported or undetected entirely, meaning the true scope of Lazarus's operations could be substantially higher than any public accounting suggests. The firm's willingness to acknowledge this gap reflects the reality that cybersecurity visibility remains incomplete, even among the most capable defenders.

The investigation into the Upbit breach is already underway. South Korean authorities have indicated they plan to conduct an on-site investigation at the exchange, working from the assumption that Lazarus bears responsibility. The investigation will likely focus on how the attackers gained initial access, what persistence mechanisms they established, and how long they may have maintained presence within Upbit's systems before executing the theft. Each of these questions carries implications not just for Upbit but for the broader cryptocurrency sector in South Korea, where exchanges have become increasingly attractive targets for state-sponsored actors seeking to acquire hard currency and digital assets.

Lazarus has long been associated with North Korea's broader cyber operations strategy. The group has been linked to some of the most consequential cyberattacks of the past decade, including the 2014 breach of Sony Pictures and the 2016 theft of $81 million from the Bangladesh central bank. What distinguishes the group from purely criminal hacking operations is its apparent alignment with state interests—attacks that serve both financial and intelligence-gathering objectives. The Upbit breach, if confirmed as Lazarus's work, fits this pattern: it generates immediate financial gain while simultaneously testing the defenses of critical financial infrastructure.

For South Korea, the findings underscore a persistent vulnerability. The country hosts some of the world's largest cryptocurrency exchanges and maintains significant digital infrastructure, making it an attractive target for adversaries seeking both economic gain and strategic advantage. The fact that Lazarus has been able to conduct at least 31 separate operations over a single year, with one resulting in a theft of tens of millions of dollars, suggests that current defensive measures—while sophisticated—remain insufficient against determined, well-resourced state actors. The coming weeks will reveal whether the on-site investigation produces evidence that definitively links Lazarus to the Upbit incident, and whether that evidence yields any insights into how the group might be disrupted or deterred.

The actual number of attacks could be higher than disclosed due to the sophisticated methods used by APT groups.
— AhnLab Inc., security assessment
Dunamu confirmed the transfer of 44.5 billion won worth of Solana-affiliated assets to an unauthorized wallet and plans to cover the full amount with assets the company owns.
— Dunamu statement
Contact Us FAQ