How North Korea Earns
Every other view on this site groups adversaries by who they are, where the victim sits, or which industry was hit. This one groups by why.
Lazarus and APT38 and TraderTraitor stealing cryptocurrency, Contagious Interview and Famous Chollima and Jasper Sleet placing fraudulent remote workers, Andariel and Moonstone Sleet deploying ransomware for cash — these are usually published as separate APT profiles. Read as a portfolio they are one funding operation with shared tooling and overlapping infrastructure, and the tooling overlap is visible in the graph below rather than asserted in prose.
This is a reference sheet, not a feed, and it is built that way deliberately. Espionage and fraud do not appear on ransomware leak sites and are rarely the subject of a public breach notification, so the twenty-three DPRK-origin groups we track hold almost no rows in an incident corpus of more than eighteen thousand. The substantive record here is the vendor reporting, the tooling and our own coverage — not a victim count, which for this set would be a measure of our sources and not of the operation.
- Curated entries: 18
- 24 linked briefings
What these have in common
Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.
ATT&CK techniques
- Acquire Infrastructure: Domains (T1583.001) 4/5 here · 44/171 tracked
- Phishing: Spearphishing via Service (T1566.003) 3/5 here · 14/171 tracked
- User Execution: Malicious File (T1204.002) 5/5 here · 86/171 tracked
- Establish Accounts: Social Media Accounts (T1585.001) 3/5 here · 18/171 tracked
- Establish Accounts: Email Accounts (T1585.002) 3/5 here · 19/171 tracked
- System Information Discovery (T1082) 4/5 here · 57/171 tracked
- Develop Capabilities: Malware (T1587.001) 3/5 here · 24/171 tracked
- Drive-by Compromise (T1189) 3/5 here · 31/171 tracked
- Disable or Modify Tools (T1685) 3/5 here · 32/171 tracked
- System Network Connections Discovery (T1049) 3/5 here · 32/171 tracked
Shared tooling
- ECCENTRICBANDWAGON 2/5 here · 2/157 tracked
- HOPLIGHT 2/5 here · 2/157 tracked
Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.
Groups
Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.
- Lazarus Group 1 incident — APT · North Korea — 2025-02-21 — The umbrella designation; crypto theft at the largest scale we record.
- APT38 0 incidents — APT · North Korea — The financial arm proper.
- TraderTraitor 0 incidents — APT · North Korea — Exchange and supply-chain compromise for cryptocurrency.
- Contagious Interview 0 incidents — APT · North Korea — Fake recruiting pipelines against developers.
- Famous Chollima 0 incidents — APT · North Korea — Fraudulent remote-worker placement.
- Jasper Sleet 0 incidents — APT · North Korea — The same programme under a Microsoft designation.
- Moonstone Sleet 0 incidents — APT · North Korea — Ransomware deployed for cash rather than disruption.
- Andariel 0 incidents — APT · North Korea — Mixed-motive: most of our coverage is espionage, included for the ransomware.
- ELUSIVE COMET 0 incidents — APT · North Korea — Social-engineering-led cryptocurrency theft.
Malware and tooling
- BeaverTail 1 group — Malware — First-stage loader in the fake-interview chain.
- InvisibleFerret 1 group — Malware — Second stage, paired with the above.
- XORIndex Loader 1 group — Malware — Package-registry loader.
- AppleJeus 1 group — Malware — Trojanised trading software; the original crypto-theft delivery.
Sectors
- Cryptocurrency & Blockchain Commercial — The victim side of this operation, from the other direction.
Further reading
- TraderTraitor (Lazarus/UNC4899): JumpCloud Supply Chain Compromise, Bybit $1.5B Safe{Wallet} AWS Session Token Theft, and DMM Bitcoin $308M RN Stealer Campaign Nation-State — 2026-02-16
- Lazarus Contagious Interview Deploys Tsunami Framework: Modular Malware Uses TOR and Pastebin for C2 in Cryptocurrency Theft Campaign Nation-State — 2026-02-16
- North Korean hackers hide malware in SVG flags to trap developers Nation-State — 2026-07-17
- North Korean IT Workers and the AI-Enabled Attack Chain: Inside Microsoft's Threat Intelligence Report AI Security — 2026-03-06
Our coverage
The 12 most recent of 24 briefings that mention a member of this collection.
- Korean firms hit by backdoor tied to North Korean hackers 2026-08-06
- Attackers weaponize most public exploits within 48 hours 2026-08-03
- Hackers now poison open source packages instead of breaking into vendors 2026-07-31
- Hacked Korean websites pushed spy backdoors and Gunra ransomware 2026-07-30
- North Korean hackers hide malware in SVG flags to trap developers 2026-07-17
- State-backed hackers hide attacks inside AI tools and trusted cloud apps 2026-07-14
- Fake Cloudflare page hidden in an npm package redirects victims to a phishing site 2026-07-05
- CISA warns of critical flaws across industrial control systems 2026-06-30
- China-linked groups drive most state-backed attacks on tech firms 2026-06-10
- North Korean IT Workers and the AI-Enabled Attack Chain: Inside Microsoft's Threat Intelligence Report 2026-03-06
- ScoringMathTea: Inside Lazarus Group's Modular RAT with Reflective Plugin Loading and PEB-Walking API Evasion 2026-02-16
- Lazarus Group Targets Aerospace and Defense with New Comebacker Variant: ChaCha20 Encryption and AES-Encrypted C2 Mark Evolving Tradecraft 2026-02-16
How this list was chosen. Membership is by attributed origin and by assessed motive, drawn from vendor reporting we hold on file — FBI IC3, CISA advisories, Microsoft MSTIC, Mandiant, CrowdStrike, Kaspersky, Unit 42 and others. Andariel is genuinely mixed-motive and most of our own coverage of it concerns defence espionage rather than revenue; it is included for the ransomware activity specifically. The malware list is curated rather than joined: the ATT&CK software catalogue is anchored on families from the late 2010s while the loaders named in our 2026 reporting are newer than it. Nothing here names an individual job applicant or an employer, and nothing does so outside a cited public advisory.
Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.