> ## Content Index
> Fetch the complete content index at: https://www.russianhackers.co/llms.txt
> Use this file to discover other available public pages before exploring further.

# $643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out
- URL: https://www.russianhackers.co/lazarus-643m-h1-2026-operations-attribution-limits/
- Published: 2026-07-20T18:31:36.000Z
- Updated: 2026-07-20T18:31:36.000Z
- Author: Martin
- Tags: Hackers, Breaches

In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34 billion across 47 incidents, 61% of all funds stolen that year and double the 2023 figure of $660.5 million.

More than one group sits behind those numbers. Lazarus long ago became an umbrella term, with different researchers describing different activity clusters under it.

## The names behind the name

Official documents tend to use narrower labels. The joint statement issued on 23 December 2024 by the FBI, the Defense Department's Cyber Crime Center (DC3) and Japan's National Police Agency names TraderTraitor, and notes the same cluster is tracked as Jade Sleet, UNC4899 and Slow Pisces. Japan's own domestic alert, published the next day with the NISC cybersecurity centre and the Financial Services Agency, adds that TraderTraitor is considered part of the Lazarus Group, which it describes as subordinate to the North Korean authorities.

The label PUKCHONG, often attached to that same advisory, does not appear in the FBI text at all. It is Google's designation for UNC4899 and entered the alias stack through later secondary coverage. Retellings of these reports routinely add attribution the reports themselves do not contain.

## Anatomy of one operation

The best documented operation remains the theft from Japanese exchange DMM Bitcoin. According to the FBI, DC3 and the NPA, 4,502.9 BTC left the exchange in late May 2024, valued at $308 million at the time of the attack. The Japanese alert gives the same amount in yen, about 48.2 billion, while Chainalysis, publishing four days before the FBI statement, put it at $305 million. The spread comes from different valuation dates, and the bitcoin figure is identical everywhere.

The attack itself never touched the exchange. In late March 2024, someone posing as a recruiter on LinkedIn contacted an employee of Ginco, a Japanese company that builds enterprise cryptocurrency wallet software. The target was offered a pre-employment test and sent a link to a Python script hosted on GitHub. The compromise step is spelled out in the statement: the employee copied the code to their own GitHub page and was compromised as a result. By mid-May the attackers were using session cookie data to impersonate that employee and reach Ginco's unencrypted communications system. In late May, as the FBI phrases it, they likely used that access to manipulate a legitimate transaction request made by a DMM employee.

The agency does not present the transaction manipulation as established fact, and that qualifier disappears in most retellings. The Japanese document, which never names Ginco, describes the lure more precisely: the attacker commits a program that calls a simple API, complains that it is broken, and asks the target to debug it. One of the API endpoints belongs to the attacker, and the code execution routine hides inside the function that processes the response.

Wiz later reported the tooling involved, RN Loader and RN Stealer, harvesting SSH keys, saved credentials and cloud configuration files. That detail appears in no government document.

## The shift into the supply chain

The DMM theft shows the broader move. Exchanges learned to defend a perimeter, and a contractor with access to their infrastructure has no such defence.

In July 2023 GitHub's Security Lab described a campaign in which fake developer and recruiter personas invited targets to collaborate on repositories whose npm dependencies were malicious, with a pair of packages that only detonated when installed together. Four GitHub accounts and seventeen npm accounts were named.

The most technically grounded attribution belongs to Japan's JPCERT/CC, which in February 2024 dissected four PyPI packages: pycryptoenv, pycryptoconf, quasarlib and swapmempool. A file named test.py turned out to be an XOR-encoded DLL executed through rundll32, with the Comebacker backdoor as the final payload. The North Korean link came not from matching tradecraft but from a binary artefact: a distinctive 66 66 66 66 padding pattern that also appears in BLINDINGCAN, an implant previously attributed by the US agency CISA.

The recruitment campaign known as Contagious Interview was tracked in Unit 42's original November 2023 report as CL-STA-0240, pairing the BeaverTail loader with the cross-platform InvisibleFerret backdoor. A detail rarely repeated: its authors assessed state sponsorship at only moderate confidence, against high confidence for the parallel Wagemole operation.

## What changed by 2026

Reports from 2026 record three changes in tradecraft.

First: patience. In February 2026 ReversingLabs described a campaign spanning the graphalgo and bigmath package families on npm and PyPI, in which bigmathutils spent more than nine months building a reputation and passed ten thousand downloads before version 1.1.0 shipped a payload. The command server answered only requests carrying a valid token, and the RAT existed in JavaScript, Python and VBS variants, with the ability to detect MetaMask. The cover story was a non-existent firm called Veltrix Capital, with domains registered a year before the campaign.

Second: compromising legitimate maintainers instead of publishing their own packages. In May 2026 Socket documented the Packagist package roberts/leads, where malicious code reached a branch through the developer's own access.

Third: abandoning conventional command infrastructure. In the PolinRider campaign, analysed by Socket in July 2026, the encrypted second stage was pulled not from a domain but through public RPC services on the TRON, Aptos and BNB Smart Chain networks. That channel cannot be taken down with a complaint to a registrar. The campaign spanned 162 malicious artefacts across 108 packages and extensions, including roughly eighty Go modules, with traces hidden by rewriting commit history.

Operators increasingly skip registries altogether. In the Slow Pisces campaign, described by Unit 42 in April 2025, there were no packages at all: tasks went out over LinkedIn as Python challenges hosted on GitHub, and the payload was served only when address, geolocation, time window and request headers matched, existing solely in memory. A separate 2026 thread abuses task auto-run in Visual Studio Code, where configuration files in a .vscode directory fire when a cloned repository is opened.

## Where the evidence runs out

How firmly the chain runs from a discovered package to a state gets discussed far less than the findings themselves.

JPCERT/CC's analysis rests on matching binary code. Other reports rest on matching tradecraft and on commit timezones: in the ReversingLabs write-up of graphalgo, one supporting argument is GMT+9 timestamps, a marker that is trivial to forge.

There are also direct gaps between a report and its retelling. Analysing the VMConnect campaign on PyPI, ReversingLabs stated plainly that it could not definitively attribute the activity to any specific actor, with the North Korean link running through a third party's attribution of separate malware. The press covered it as packages published by Lazarus hackers.

The reverse error occurs too. TrapDoor, examined by Socket in May 2026, and TigerJack, aimed at code editor extensions, both targeted the same cryptocurrency developers, yet North Korea appears nowhere in their authors' reports. An interest in wallets and keys is not by itself a signature of a state group.

## Who counts now

The international machinery for monitoring sanctions on North Korea has meanwhile stopped existing in its former shape. The UN Panel of Experts published its final report, S/2024/215, on 7 March 2024, Russia blocked renewal of its mandate on 28 March, and the mandate expired on 30 April 2024\. Among other things, that makes any citation of Panel of Experts reporting on the DMM Bitcoin theft unsound, because the mandate ended before the theft occurred.

Part of the monitoring role passed to the Multilateral Sanctions Monitoring Team, established in October 2024 with eleven participating states. Its second report, covering cyber operations and North Korean IT worker activity, was published on 22 October 2025.

## What follows for defence

In most of the documented cases the attack began with a developer who ran the code they were sent. No vulnerability was required.

Recruiter test assignments belong in an isolated environment with no access to working credentials or keys. Package installation should not happen where production secrets are available, and dependencies are worth pinning to specific versions, since the 2026 campaigns exploit the update of a previously harmless package. Task auto-run on opening a repository should be switched off. Download counts no longer work as a safety signal, because bigmathutils earned its ten thousand downloads while it was clean.

*Based on reporting by TRM Labs, Chainalysis, the FBI, DC3, Japan's National Police Agency, JPCERT/CC, Unit 42, GitHub Security Lab, ReversingLabs and Socket.*