The North Korean Hacker Army Stealing Billions
44sOpens with jaw-dropping scale of state-sponsored cybercrime and nuclear missile funding, instantly hooking viewers.
▶ Play Clip"Delivers exactly what the title promises, though padded with channel promos and some filler."
This video provides a comprehensive analysis of the Lazarus Group, a North Korean cybercriminal organization responsible for billions of dollars in thefts from banks and cryptocurrency exchanges. It covers the group's origins, structure, training methods, and major attacks including the Sony hack, the Bangladesh Bank heist, and the WannaCry ransomware attack.
The Lazarus Group is a North Korean hacker collective that has stolen billions from banks and cryptocurrency exchanges. It is also responsible for leaking movie scripts and personal data from Sony, and likely operates on orders from the North Korean government to fund military programs despite sanctions.
Also known as Guardians of Peace or Z Team, the group originates from North Korea and may include up to 7,000 trained hackers. The US government calls it Cobra, Microsoft calls it Diamond Sleet, and internally it is known as the 414 Liaison Office.
Hackers receive specialized training in Shenyang, China, and at Kim Chaek and Kim Il-sung universities. The Chulbasan Hotel in Shenyang was used as an operations base until it was closed by Chinese authorities on January 9, 2018.
Bluenor (1,700 members) focuses on financial cybercrime using fake SWIFT orders, while Andariel (1,600 members) targets South Korea's government, defense, and economic infrastructure for reconnaissance and attacks.
The group's first major attacks hit US websites including the NYSE, Amazon, and The Washington Post on July 4, 2009, and South Korean government sites on July 7. They used a botnet of 20,000-50,000 infected computers.
Posing as Guardians of Peace, hackers leaked employee personal data, emails, unreleased films, and scripts, then wiped Sony's infrastructure. The motive was to stop the release of 'The Interview,' a comedy about assassinating Kim Jong-un.
Attackers sent 35 fake SWIFT instructions to transfer nearly $1 billion from the Bangladesh Bank account at the Federal Reserve Bank. Due to errors, only $100 million was stolen, making it a partial failure.
A worm-based ransomware hit over 200,000 computers in 150 countries, encrypting files and demanding $300 in Bitcoin. It was stopped by a kill-switch domain registered by researchers. The low $160k payout suggests disruption, not profit, as the motive.
Recorded Future linked Lazarus to attacks targeting cryptocurrency users. The group stole $7 million from Bithumb in 2017, bankrupted Youbit, and later stole $620 million from the Ron Network and $100 million from the Horizon bridge.
In 2021, Microsoft and Google reported that Lazarus created fake researcher profiles on Twitter, GitHub, and LinkedIn to attempt to trick cybersecurity experts into downloading malware, exploiting zero-days.
The Lazarus Group remains one of the most prolific and dangerous cybercriminal organizations, evolving from DDoS attacks to sophisticated bank heists and cryptocurrency thefts. Its actions are not merely criminal but serve as a state-backed tool for revenue generation and asymmetric warfare.
What is the Lazarus Group?
A North Korean hacker group also known as Guardians of Peace, possibly with up to 7,000 members.
01:30
What are the two main subunits of the Lazarus Group?
Bluenor, which focuses on financial crime, and Andariel, which targets South Korea.
03:01
How did the Bangladesh Bank attack work?
Hackers sent 35 fake SWIFT instructions to transfer nearly $1 billion, but only $100 million went through due to errors.
08:47
What was the WannaCry ransom amount?
$300 in Bitcoin.
12:09
What was the kill switch for WannaCry?
A domain name registered by a security researcher stopped the malware from spreading.
13:08
Which US agency developed the vulnerability exploited by WannaCry?
The NSA.
14:20
Why did the Microsoft patch not protect users from WannaCry?
The update was not included in mandatory updates, so most users were unprotected.
15:02
How much did the Ron Network lose to Lazarus?
$620 million in cryptocurrency.
18:09
What social engineering tactic did Lazarus use on security researchers?
They created fake profiles on Twitter, GitHub, and LinkedIn posing as vulnerability researchers.
16:46
What was the motive behind the Sony Pictures hack?
To force Sony to cancel 'The Interview,' a film about assassinating Kim Jong-un.
07:48
Lazarus Group is structured into two specialized units
Understanding the division explains the group's diverse attack capabilities, from financial fraud to espionage.
03:01Bangladesh Bank heist demonstrated the power of SWIFT fraud
A landmark heist showing how cybercriminals can move real money via the global banking system.
08:47WannaCry was likely a North Korean operation for disruption, not profit
The low ransom payout and the kill switch suggest state-sponsored chaos rather than financial gain.
10:29North Korea uses crypto theft to evade sanctions
This highlights a modern financial warfare tactic that bypasses traditional banking restrictions.
15:18Social engineering targets cybersecurity experts
Even professionals with state-of-the-art security can be compromised by convincing fake personas.
16:33[00:02] group Lazarus, which is responsible for spreading cybercriminal chaos across the world. Over the course of many years, they stole billions of dollars from banks and cryptocurrency exchanges. They are also guilty of leaking movie scripts or
[00:17] personal data of giants like Sony. And all of this is probably happening on orders from North Korea, because that's where the most talented, specially trained hackers have access to the internet. In this way,
[00:31] North Korean authorities obtain funding for the development of military technologies such as nuclear missiles, despite international sanctions, while simultaneously coordinating asymmetrical cyberwarfare against regional states such as
[00:46] South Korea. Because war now does n't just take place in the trenches; it turns out it can actually take place online. I invite you to our dark archive. Don't switch. This is an analysis of the Lazas group. To use
[01:02] Lazarus properly and avoid hacking anyone , be sure to visit our Telegram channel. There are already a bunch of articles there with options for safe work for absolutely everyone. We check all offers for you, and you work
[01:15] safely. The link will be the first in the description below this video. Also look for the post under the hashtag Navigator. There will be absolutely all links to our checks. Go ahead, and we'll move on. Lazarus Group, also known as Guardians of Peace
[01:30] or Z Team, is a coordinated hacker group consisting of an unspecified number of individuals that most likely originates from North Korea. Some sources say the group may even include 7,000
[01:47] highly trained hackers. In fact, the details of the group's internal activities are shrouded in great secrecy. Although we know quite a lot of information about them, we cannot be 100% sure of it. But many
[02:01] intelligence groups classify them as an ongoing threat. This is why the group is referred to as Cobra by the US government and by Microsoft as Diamond le. According to North Korean sources and leakers such as
[02:16] Kim Kuk-sung, the group is known internally as the 414 Liaison Office under North Korea's General Intelligence Bureau. North Korean hackers are being sent to Shenyang, China, for specialized training. There they are taught all sorts of evil things, such as how
[02:33] to introduce all kinds of malicious software into computer networks or servers, and so on. The domestic education of such hackers is also being prepared at the Kimchak Technological University or
[02:46] Kimchak Technological University or Kimersen University. In 2004, one traveler indicated the Chulbasan hotel. This is a North Korean hotel in Shenyang, China, which is one of the bases of operations for the Lazarus Group. And what's interesting is that on January 9,
[03:01] 2018, this hotel was suddenly closed by Chinese authorities. What is most interesting, however, is that it is generally accepted that the Lazarus group is divided into at least two units. The first is the Bluenors group, a strictly financially motivated group
[03:16] money transfers using fake SWIFT orders. According to a SWIFT orders. According to a 2020 US Army report, Bluenor has approximately 1,700 members who operate in financial cybercrime,
[03:30] focusing on long-term assessment and exploitation of vulnerabilities in enemy networks and systems to achieve financial gain for the regime or to seize control of their victims' systems. The victims are primarily
[03:45] all kinds of financial institutions, as well as cryptocurrency exchanges in more than sixteen organizations in at least thirteen countries. We are talking here, by the way, about Bangladesh, India, Poland, Mexico, Pakistan and a bunch of
[04:01] other countries. The second subgroup of Lazarus is the so-called Adereail. This particular unit is particularly characterized by the fact that it attacks mainly South Korea and countries in the region. Every organization in South Korea is
[04:15] literally vulnerable to Underil attacks. The targets are the government, defense and everything related to the economic part of the country. According to the same US Army report, in 2020, Ander had approximately 1,600 members whose mission
[04:32] is reconnaissance, assessing vulnerabilities in network defenses, and corroborating enemy networks for potential attacks. Besides South Korea, they sometimes attack other governments, their infrastructure and companies. Cybercrime researchers
[04:48] date the Lazarus group's origins to the late 2000s. Their first attacks are attributed to the years 2007-2010. They use literally the whole gamut from less to more sophisticated methods in order to attack as effectively as possible. According to the
[05:05] attack as effectively as possible. According to the global cybersecurity and finance the Kim Jong Un regime, despite international sanctions. Therefore, no
[05:23] knows with 100% certainty what kind of hacker attacks North Korea might actually be behind. The first actions attributed to the Lazarus group were aimed directly at the military structures and governments of the United States, as well as South Korea and governments of the United States, as well as South Korea and Dedosataki on their websites. In the United States, July 4,
[05:37] and Dedosataki on their websites. In the United States, July 4, 2009, is Independence Day, and literally various government websites were affected, as well as the websites of the New York exchange Amazon and the media giant The Washington Post in
[05:49] South Korea. A little later, on July 7, government websites, including those of all ministries, fell victim. The attack plan was relatively simple. Losarus in South Korea created a batnet, which then
[06:04] massively connected these computers to selected websites under attack, overloading their servers. The number of computers infected and captured for this purpose fluctuated sharply from literally 20 to 50,000. Interestingly, the
[06:18] malware used to infect the computers was placed in their Master Boot Code, literally in the boot data of their hard drives. The lyrics " Memory of Independence Day" directly
[06:32] referenced the American independence holiday of July 4th. The Lazaus Group also attacked the infrastructure of South Korean organizations at least several times over the following years. Such DDoS attacks also occurred in
[06:47] 2011 and later in 2013, where other, more sophisticated techniques were used that could directly damage a lot of important computer data. Sonya's War. On November 24, 2014, a group of
[07:05] hackers posing as Guardians of the Peace leaked a trove of confidential information from Sony Pictures. The leaks included personal information about employees and their families, email correspondence between employees, and
[07:19] information about the salaries of senior management at the company. But that's not all, because in addition to data related to employees, unreleased films from the studio at that time were also leaked , as well as all plans for
[07:33] future films or the scripts for some projects. After publishing sensitive information, the perpetrators used specific malware to wipe Sony's computer infrastructure . The motive was the demand that
[07:48] Sonya withdraw the then upcoming film The Interview as soon as possible, in which James Franca and Seth Rogen were supposed to meet with the leader of North Korea to carry out an assassination operation against him . Hackers also threatened
[08:02] terrorist attacks on movie theaters that would distribute the films. In response to the news, major US cinema chains pulled out of the interview, and Sony postponed the film's formal theatrical release
[08:16] to focus on digital distribution. US intelligence agencies have acknowledged that after assessing the techniques and analyzing the sources of the hack, which the agency, of course, categorically denied, the opinion of
[08:32] cybersecurity experts is divided, and some doubt North Korea's involvement in the whole affair. But over the years, some experts have directly acknowledged the connection between these events and Lazarus. The role of the hacker network in North Korea, as
[08:47] previously stated, may primarily be to finance the regime. This is the most important thing that is there now. In their country, the group carried out numerous attacks on banks over many years, stealing hundreds of millions of dollars in total.
[09:02] Consider, for example, the attack on an account belonging to the Central Bank of Bangladesh in February 2016. It was there that hackers entered 35 fake instructions into the Swift system to illegally transfer nearly $1 billion from the
[09:16] Bangladesh Bank account held at the Federal Reserve Bank to their own accounts scattered literally all over the world. This is Sri Lanka, the Philippines and so on and so forth. Due to the fact that several instructions
[09:30] were written with errors and the transaction amounts were quite large, the bankers manually stopped most of the transactions. However, five out of three p's did pass, and thus more than 100 million dollars simply evaporated,
[09:46] disappeared. But in fairness, the money was partially returned before 2018. And this entire attack can be considered a failure for the hackers. But the group has stolen, is stealing and will probably continue to steal. Therefore, such momentary mistakes are
[10:01] not yet victory in the war. A banal example. A year earlier, hackers stole $12 million from a bank in Ecuador and $1 million from a bank in Vietnam. They
[10:13] also targeted banks in Mexico and Poland. In 2017, $60 million was also stolen from a bank in Taiwan. And if you want to know how they did it, how it all happens, follow the end credits in this video. There are the last 20
[10:29] seconds of this video, there will be a link to the next video. But obviously, watch this one to the end. The largest attack on the entire world. 7:19. That's how long one of the most powerful hacker attacks in the world lasted. The main
[10:45] suspect was the Lazarus group. The victims included organizations and institutions around the world, from health services to large factories and corporations or universities. This particular attack is estimated to
[10:59] have affected over 200,000 computers in over 150 countries, primarily in Russia, India, Ukraine and Taiwan. It was also one of the first
[11:11] examples of a so-called worm attack being deployed on such a wide audience. A worm is a type of malware that moves between computers via a network without requiring any user intervention or error
[11:25] to further infect. Therefore, you don’t even need to sneeze for your neighbor to be sick. This is roughly how it works. It's enough for the worm that the victim knows your Wi-Fi password because, I don't know, it came to have coffee
[11:41] with you a week earlier. Certain specific holes and errors allowed this worm to spread directly through the internal computer networks of various organizations and very quickly infect tens of thousands of computers. The method of
[11:55] action of this particular virus was as follows. Using a hole in the Windows system, he walked around the computer and encrypted everything that came his way. To decrypt the encrypted files, you had to pay $300 in
[12:09] Bitcoin to receive the key and a file recovery tool. But what if people simply didn’t want to pay? Here, in order to force people to actually pay, the ransom demand appeared after 3 days. If
[12:24] payment was not made within a week, the malware would delete all files on the computer, and a warning would be issued. Interestingly, this virus used completely legal and publicly available
[12:38] Windows Crypto software from Microsoft to encrypt files. After the file was encrypted, Cry was added to its name , which is where , which is where the name One Cry actually came from. The attack
[12:52] only ended when a copy of the virus from a friend at a security firm. Then he opened the virus-encoded, well, the so-called emergency
[13:08] switch, let's call it that. Nankray periodically checked whether a particular Domina name was registered , and continued encrypting files and infecting subsequent users only when the Domina name did not exist.
[13:22] Hachins immediately registered this domain, and the malware immediately stopped spreading and infecting new computers. This kind of malware, which requires literally months of hard work to figure out how to
[13:36] work against the virus, somehow stumped researchers. Another very interesting and unusual aspect of the attack was that the files could not be recovered after the ransom was paid. The entire operation only raised a
[13:50] paltry $160,000, leading many to believe the hackers were n't doing it for the money. It's the seemingly easy kill switch, as well as the lack of any financial motivation. And at this point, most
[14:04] experts immediately saw North Korea as the instigator of the entire operation, and the goal was to cause general chaos. Interestingly, the bugs and vulnerabilities exploited by the hackers had been exploited earlier by several individuals and
[14:20] organizations. The vulnerability that allowed such a powerful attack to be carried out was developed by the American NSA as a cyber-weapon . The National Security Agency kept the information top secret, but the information was apparently
[14:33] stolen by the Shadow Brokers hacker group, who first tried to sell it by putting it up for auction, and after unsuccessful attempts to sell it, made it publicly available for free. The NSA then disclosed the vulnerability to
[14:49] . However, these actions did not help at all. The Microsoft update that patched key vulnerabilities was not included in the list of mandatory updates, so most users were
[15:02] still unprotected on the day of the attack , which is what made the UAN Edge attack so effective. The US Department of Justice and British authorities later attributed the attack to the North Korean hacker group Lazarus. In 2018,
[15:18] cybersecurity firm Recorded Future published a special report directly linking the LZA group to attacks primarily targeting South Korean users of the cryptocurrency Monero, as well
[15:31] as Bitcoin. It was established that these attacks were technically similar to previous attacks on Sony and the Uanan C attacks. Hackers used various vulnerabilities and several social engineering techniques to steal data, logins, and passwords from
[15:47] cryptocurrency exchanges, thereby stealing accounts containing crypto. The report also found that North Korea is using cryptocurrency-stealing attacks to evade international sanctions. It is also known that North Korean
[16:00] hackers stole $7 million from the South Korean exchange Bitham in February 2017. Another South Korean exchange, UBIT, even declared bankruptcy in UBIT, even declared bankruptcy in December 2017 after 17% of its
[16:16] assets were stolen in a cyberattack that occurred in April 2017. Lazarus was apparently blamed for the attacks . On top of all this, the cryptocurrency cloud mining market lost more than 4,500 bitcoins in December 2017
[16:33] . The investigations into these cases resulted in one conclusion. It was resulted in one conclusion. It was Lazarus. In early 2021, Microsoft and Google publicly reported on a group of North Korean hackers who used
[16:46] social engineering to attack cybersecurity experts. Microsoft almost immediately admitted that it must be the Lazarus group. The course of action was as follows. Hackers created multiple profiles on Twitter, GitHub, and
[17:02] LinkedIn, posing as genuine software vulnerability researchers . These profiles were then used to interact with posts and content created by other members of the cybersecurity expert community
[17:16] , as well as under the guise of offers of research collaboration. They tried to persuade the victim to download a file containing malware or to visit a post on the block below the
[17:29] page, which obviously would not lead to anything good either. Apparently, victims quickly emerged who, after visiting a blog post, reported that their computers had indeed been hacked,
[17:42] even though they were using the latest security systems that were free of the well-known vulnerabilities in the Google Chrome browser. Therefore, the conclusion is simple. The hackers weren't stupid;
[17:55] they probably used vulnerabilities like Zay, which no one had yet patched. Google added in the message that it was unable to confirm the exact method used to hack the victim's computer. Lolaza's group was behind even more attacks.
[18:09] In March 2020, they stole $620 million worth of cryptocurrency from the Ron Network. This is a bridge that uses the Axy Infinity game blockchain. The FBI also confirmed Lazarus's involvement in another theft, when
[18:25] $100 million in virtual currency disappeared from the Horizеon cryptocurrency bridge to from the Horizеon cryptocurrency bridge to Harney in June 2022. In 2023, Attoomic Wallet users lost over $100 million worth of cryptocurrency.
[18:39] In September of the same year, the FBI also confirmed that the Lazarus group had committed the theft of cryptocurrency worth 41 million dollars from the online casino and bookmaker Steak, and so on, and so forth. In short, I think you've
[18:52] realized that this group is taking money from everyone it can reach: from banks and small wallets to entire exchanges and crypto bridges. If you found this interesting, be sure to like this video and subscribe to the channel.
[19:07] See you in our dark archive in the next videos. Also navigate through the video next videos. Also navigate through the video on the screen.
⚡ Saved you 0h 19m reading this? Transcribe any YouTube video for free — no signup needed.