How North Korea Earns
Every other view on this site groups adversaries by who they are, where the victim sits, or which industry was hit. This one groups by why.
Lazarus and APT38 and TraderTraitor stealing cryptocurrency, Contagious Interview and Famous Chollima and Jasper Sleet placing fraudulent remote workers, Andariel and Moonstone Sleet deploying ransomware for cash — these are usually published as separate APT profiles. Read as a portfolio they are one funding operation with shared tooling and overlapping infrastructure, and the tooling overlap is visible in the graph below rather than asserted in prose.
This is a reference sheet, not a feed, and it is built that way deliberately. Espionage and fraud do not appear on ransomware leak sites and are rarely the subject of a public breach notification, so the twenty-two DPRK-origin groups we track hold almost no rows in an incident corpus of more than nineteen thousand. The substantive record here is the vendor reporting, the tooling and our own coverage — not a victim count, which for this set would be a measure of our sources and not of the operation.
- Curated entries: 18
- 33 linked briefings
What these have in common
Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.
ATT&CK techniques
- Acquire Infrastructure: Domains (T1583.001) 4/5 here · 47/191 tracked
- User Execution: Malicious File (T1204.002) 5/5 here · 88/191 tracked
- Phishing: Spearphishing via Service (T1566.003) 3/5 here · 14/191 tracked
- Establish Accounts: Social Media Accounts (T1585.001) 3/5 here · 19/191 tracked
- Establish Accounts: Email Accounts (T1585.002) 3/5 here · 20/191 tracked
- System Information Discovery (T1082) 4/5 here · 63/191 tracked
- Develop Capabilities: Malware (T1587.001) 3/5 here · 26/191 tracked
- Drive-by Compromise (T1189) 3/5 here · 33/191 tracked
- System Network Connections Discovery (T1049) 3/5 here · 33/191 tracked
- Disable or Modify Tools (T1685) 3/5 here · 39/191 tracked
Shared tooling
- BeaverTail 2/6 here · 2/255 tracked
- Dtrack 2/6 here · 2/255 tracked
- ECCENTRICBANDWAGON 2/6 here · 2/255 tracked
- HOPLIGHT 2/6 here · 2/255 tracked
- InvisibleFerret 2/6 here · 2/255 tracked
- MagicRAT 2/6 here · 2/255 tracked
Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.
Groups
Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.
- Lazarus Group 1 incident — APT · North Korea — 2025-02-21 — The umbrella designation; crypto theft at the largest scale we record.
- APT38 0 incidents — APT · North Korea — The financial arm proper.
- TraderTraitor 0 incidents — APT · North Korea — Exchange and supply-chain compromise for cryptocurrency.
- Contagious Interview 0 incidents — APT · North Korea — Fake recruiting pipelines against developers.
- Famous Chollima 0 incidents — APT · North Korea — Fraudulent remote-worker placement.
- Jasper Sleet 0 incidents — APT · North Korea — The same programme under a Microsoft designation.
- Moonstone Sleet 0 incidents — APT · North Korea — Ransomware deployed for cash rather than disruption.
- Andariel 0 incidents — APT · North Korea — Mixed-motive: most of our coverage is espionage, included for the ransomware.
- ELUSIVE COMET 0 incidents — APT · North Korea — Social-engineering-led cryptocurrency theft.
Malware and tooling
- BeaverTail 2 groups — Malware — First-stage loader in the fake-interview chain.
- InvisibleFerret 2 groups — Malware — Second stage, paired with the above.
- XORIndex Loader 1 group — Malware — Package-registry loader.
- AppleJeus 1 group — Malware — Trojanised trading software; the original crypto-theft delivery.
Sectors
- Cryptocurrency & Blockchain 14 incidents — Commercial — The victim side of this operation, from the other direction.
Further reading
- TraderTraitor (Lazarus/UNC4899): JumpCloud Supply Chain Compromise, Bybit $1.5B Safe{Wallet} AWS Session Token Theft, and DMM Bitcoin $308M RN Stealer Campaign Nation-State — 2026-02-16
- Lazarus Contagious Interview Deploys Tsunami Framework: Modular Malware Uses TOR and Pastebin for C2 in Cryptocurrency Theft Campaign Nation-State — 2026-02-16
- North Korean hackers hide malware in SVG flags to trap developers Nation-State — 2026-07-17
- North Korean IT Workers and the AI-Enabled Attack Chain: Inside Microsoft's Threat Intelligence Report AI Security — 2026-03-06
Our coverage
The 12 most recent of 33 briefings that mention a member of this collection.
- North Korea's hacking machine is bigger than Lazarus 2026-09-07
- North Korean fake workers move into healthcare and sales 2026-08-28
- Spies and ransomware crews exploit the same edge devices 2026-08-26
- Hijacked Rust package backdoors any machine that builds it 2026-08-20
- State hackers now log in instead of dropping malware 2026-08-20
- North Korean fake hires used ChatGPT to pass interviews 2026-08-18
- Fake quote emails drop a stealer that kills antivirus 2026-08-18
- Microsoft fixes 421 flaws as new Defender zero-day drops 2026-08-12
- Lazarus used a Windows zero-day to hit defense firms 2026-08-11
- Korean firms hit by backdoor tied to North Korean hackers 2026-08-06
- Attackers weaponize most public exploits within 48 hours 2026-08-03
- Hackers now poison open source packages instead of breaking into vendors 2026-07-31
How this list was chosen. Membership is by attributed origin and by assessed motive, drawn from vendor reporting we hold on file — FBI IC3, CISA advisories, Microsoft MSTIC, Mandiant, CrowdStrike, Kaspersky, Unit 42 and others. Andariel is genuinely mixed-motive and most of our own coverage of it concerns defence espionage rather than revenue; it is included for the ransomware activity specifically. The malware list is curated rather than joined: the ATT&CK software catalogue is anchored on families from the late 2010s while the loaders named in our 2026 reporting are newer than it. Nothing here names an individual job applicant or an employer, and nothing does so outside a cited public advisory.
Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.