DPRK Cyber Espionage Knowledge Cell

SkillCommerce & finance

Use when the user asks about North Korean state-sponsored cyber operations or specific DPRK actors (Lazarus, APT38, BlueNoroff, Andariel, Kimsuky, etc.), revenue-generation campaigns, IT-worker schemes, or DPRK targeting of cryptocurrency / supply chain. Self-updating knowledge cell.

Use DPRK Cyber Espionage Knowledge Cell in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add DPRK Cyber Espionage Knowledge Cell and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the DPRK Cyber Espionage Knowledge Cell skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

DPRK Cyber Espionage Knowledge CellStart free

What this skill tells your AI

The instructions your AI receives, as published by liberty91ltd/cti-skills in skills/dprk-cyber-espionage/SKILL.md and read by Ahel’s review.

Executive Summary

North Korea operates a uniquely structured cyber program where revenue generation and intelligence collection are equally prioritized national objectives. Most units sit under the Reconnaissance General Bureau (RGB); Japanese and U.S. authorities assess that the Contagious Interview (WaterPlum) operators and some IT workers instead operate under the 313 General Bureau of the Munitions Industry Department [24]. Chainalysis puts cumulative DPRK cryptocurrency theft at $6.75 billion through the end of 2025 [11]. The Multilateral Sanctions Monitoring Team (MSMT), which replaced the disbanded UN Panel of Experts as the main multilateral reporting body, published its first cyber and IT-worker report in October 2025 [16].

2025 was the largest year on record: Chainalysis attributes $2.02 billion in theft to the DPRK, a 51% increase on 2024 from far fewer known incidents, dominated by the $1.5 billion Bybit theft of February 2025 that the FBI attributed to TraderTraitor [9][11]. 2026 has continued at a lower but still high level. The April 2026 Drift Protocol (about $285 million) and KelpDAO (about $290 million) thefts and the 24 September 2026 Bitget theft ($351.6 million) are all assessed by blockchain analytics firms or the victims as likely DPRK operations, though none has yet been formally attributed by a government. If Bitget is confirmed, 2026 theft exceeds $1 billion [19][20][21][22][23].

Three trends define the period since early 2025. First, developer and open-source targeting has become the main access route: the Contagious Interview fake-interview campaign infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026, and the March 2026 compromise of the axios npm package showed that DPRK operators can hijack packages with more than 100 million weekly downloads [17][18][24]. Second, the IT-worker scheme has drawn sustained enforcement (a coordinated U.S. action in June 2025, sanctions in March 2026, multinational alerts in July and September 2026) while expanding beyond the United States and adopting AI tools for identity fraud [13][14][15][24]. Third, espionage units continue to invest in capability: Lazarus used a Windows zero-day in its 2026 Operation Dream Job wave against defense firms, and Kimsuky compromised South Korean software vendors to reach their customers [26][27].

Key Actors

Vendor naming overlaps heavily and "Lazarus Group" is often used as an umbrella term for several units. Aliases below are those confirmed in the cited reporting.

Threat ActorAliasesAttributionPrimary TargetsStatus
Lazarus GroupDiamond Sleet, HIDDEN COBRA, Zinc, Labyrinth Chollima, Nickel AcademyRGB 3rd BureauDefense, aerospace, cryptocurrency, banksActive
APT38/BlueNoroffSapphire Sleet, Stardust Chollima, UNC1069, CageyChameleon, Alluring PiscesRGBCryptocurrency firms and executives, open-source maintainers, bankingActive
KimsukyAPT43, Emerald Sleet, Velvet Chollima, Thallium, Black BansheeRGB 5th BureauSouth Korean government and software vendors, think tanks, academics, NK policy expertsActive
AndarielAPT45, Onyx Sleet, Stonefly, Silent Chollima, Plutonium, DarkSeoulRGB 3rd BureauDefense, nuclear, aerospace, healthcare (ransomware)Active
TraderTraitorJade Sleet, UNC4899RGB-linkedCryptocurrency exchanges, wallet and bridge infrastructure providersActive
Citrine SleetUNC4736, AppleJeus, Golden Chollima, Gleaming Pisces, DEV-0139RGB-linkedDeFi protocols, cryptocurrency traders, financial technologyActive
Contagious InterviewWaterPlum, UNC5342313 General Bureau, Munitions Industry Department (NPA/FBI assessment)Software developers, freelancers, Web3 and AI job seekersActive
DPRK IT workersJasper Sleet (formerly Storm-0287)Multiple DPRK entities incl. 313 General BureauRemote technology roles worldwideActive
ScarCruftReaper, Ricochet Chollima, InkySquid, APT37MSS (State Security)South Korean government, defectors, journalists, human rightsActive

Active Campaigns

Cryptocurrency Exchange and DeFi Platform Theft (2023-Present)

DPRK operators remain the largest single source of cryptocurrency theft. Chainalysis attributes $2.02 billion to them in 2025 and notes that they accounted for 76% of all service compromises that year [11]. Confirmed and suspected operations in 2026:

  • Drift Protocol (1 April 2026): about $285 million drained in roughly 12 minutes after a social engineering effort that began in autumn 2025, with operators posing as a quantitative trading firm and meeting Drift contributors at conferences. Drift attributed it with medium confidence to UNC4736 (Citrine Sleet). TRM Labs describes DPRK involvement as likely; Elliptic gives the figure as $286 million and calls it suspected DPRK-linked [19][20][21].
  • KelpDAO (18 April 2026): about $290 million (Chainalysis: $292 million) taken by poisoning RPC nodes used by the LayerZero verifier and forcing failover with a DDoS attack. LayerZero's preliminary attribution is to TraderTraitor [22].
  • Bitget (24 September 2026): $351.6 million taken from hot wallets after attackers compromised a backend system and spoofed transaction data; private keys were not stolen. Bitget's CEO called DPRK involvement very likely. Elliptic assesses it as highly likely DPRK-linked. TRM Labs reports on-chain overlaps with Bybit laundering but has not definitively attributed it [23].

Totals differ by firm. TRM counted about $690 million attributed to the DPRK in 2026 before Bitget; Elliptic counts more than 51 incidents and over $1 billion including Bitget [23]. Laundering relies on rapid splitting into fresh wallets, cross-chain swaps and bridges, mixers, and Chinese-language money movement and guarantee services, with a typical cycle of about 45 days [11].

Contagious Interview Developer Targeting (2023-Present)

Operators pose as recruiters for AI, cryptocurrency and NFT companies and instruct candidates to run malicious code during a coding test or while "fixing" a video-conferencing error. A joint advisory by Japanese, U.S., Australian and German agencies on 18 September 2026 states that the group infected at least 30,000 devices in more than 100 countries, took funds or credentials from over 7,000 cryptocurrency wallets, and transferred about $10.71 million to the DPRK. Malware is delivered through malicious npm packages and code repositories. The advisory also notes that some operators double as IT workers and that Japan dismantled its first identified laptop farm [24]. Google reported in October 2025 that the group (UNC5342) had used EtherHiding since February 2025, storing payloads in smart contracts on BNB Smart Chain and Ethereum, the first nation-state use of the technique Google had observed [25].

Open-Source Package Compromise by BlueNoroff (2025-Present)

On 31 March 2026 attackers took over the axios npm maintainer account after a tailored social engineering approach and published two malicious versions that were live for about three hours. They installed a cross-platform backdoor through a fake dependency. Google attributes the compromise to UNC1069 and Microsoft to Sapphire Sleet [17][18]. In July 2026 Amazon attributed the axios compromise, the September 2025 hijack of the debug and chalk packages, and a March 2025 compromise of typo-crypto to the same actor with medium confidence. No other vendor has published an attribution for debug, chalk or typo-crypto [28]. Separately, Arctic Wolf attributed with high confidence a campaign against Web3 executives, first detected in January 2026, that used typo-squatted Zoom and Teams links, fake meetings populated with stolen or AI-generated video, and ClickFix clipboard injection [29].

IT Worker Fraudulent Employment Scheme (2022-Present)

DPRK IT workers continue to obtain remote employment under false identities. They are mostly located in North Korea, China and Russia, with smaller numbers in Africa and Southeast Asia [13][24]. Revenue estimates vary: earlier UN reporting put it at $250-600 million annually, while the U.S. Treasury stated in March 2026 that the scheme generated nearly $800 million in 2024 [15]. Microsoft reports that the scheme now targets technology roles across industries globally and that workers use AI for document forgery, photo enhancement and voice changing [13]. Enforcement has intensified:

  • June 2025: DOJ announced searches of 21 laptop farms in 14 states, seizure of 29 financial accounts and 21 websites, and charges in a scheme that placed workers at more than 100 U.S. companies and exposed ITAR-controlled data at a defense contractor. A separate indictment charged four DPRK nationals who stole over $900,000 from an Atlanta blockchain company while employed there [12].
  • July 2025: Christina Chapman was sentenced to 102 months for running a laptop farm that served 309 U.S. businesses and generated $17 million [14].
  • March 2026: OFAC designated six individuals and two entities, including Amnokgang Technology Development Company and facilitators in Vietnam and Laos [15].
  • July 2026: eleven governments issued a joint alert on IT-worker tactics [30].

Chainalysis notes that IT workers embedded in cryptocurrency services are increasingly used to gain privileged access for theft, not only salary revenue [11].

Lazarus Defense and Nuclear Espionage (2023-Present)

Lazarus Group and Andariel continue espionage against defense, aerospace and nuclear organizations. Check Point documented an Operation Dream Job wave running from early 2026 to July 2026 against defense-sector targets in Western Europe, India and South America, with emphasis on aerospace, drones, sensors and robotics. Fake job offers delivered a trojanized open-source PDF viewer or DLL sideloading chains. The operators used CVE-2026-68820, a Windows AFD.sys use-after-free, as a zero-day for privilege escalation; it was reported on 28 July 2026 and patched on 11 August 2026 [26]. Collected intelligence supports DPRK missile, nuclear, submarine and drone programs.

Kimsuky Espionage and Vendor Compromise (2025-Present)

Kimsuky compromised South Korean groupware vendors in 2025 and early 2026, through a mail server vulnerability in one case and social engineering in another, then used stolen customer server information to reach the vendors' customers [27]. The FBI warned in January 2026 that Kimsuky uses QR codes in spearphishing against think tanks, academia and government, moving victims to unmanaged mobile devices and stealing session tokens to bypass MFA [31]. Genians documented Kimsuky's adoption of ClickFix lures during 2025 [32].

Lazarus Overlap with Ransomware Operations (2024-Present)

Symantec reported in February 2026 that Lazarus tooling was used in Medusa ransomware intrusions against U.S. healthcare and Middle East organizations. The activity resembles Andariel (Stonefly) but the sub-group is unconfirmed [33]. In July 2026 South Korean agencies warned that Lazarus tools and infrastructure overlap with ransomware attacks on South Korean organizations; whether this reflects collaboration, shared infrastructure or access brokering is unresolved [34].

Historical Campaigns

Bybit Exchange Theft (2025)

On 21 February 2025 about $1.5 billion in Ethereum was taken from Bybit, the largest cryptocurrency theft on record. The FBI attributed it to TraderTraitor on 26 February 2025 [9]. The attackers compromised a Safe{Wallet} developer's macOS workstation on 4 February, used the developer's active AWS sessions to reach Safe{Wallet} infrastructure, and on 19 February modified JavaScript served to the wallet interface so that it altered transactions only when Bybit's cold wallet was the source. The code was removed two minutes after the theft [10].

3CX Supply Chain Attack (2023)

In March 2023 a DPRK actor compromised the build pipeline of 3CX, an enterprise VoIP/PBX provider. The intrusion began when a 3CX employee installed a trojanized X_TRADER application from Trading Technologies, itself the product of an earlier supply chain compromise. Mandiant described this as the first time it had seen one software supply chain attack lead to another, and attributed it to UNC4736, which it links with moderate confidence to AppleJeus activity; CrowdStrike attributed it to Labyrinth Chollima [3][8]. Malware included the TAXHAUL loader and COLDCAT downloader on Windows and the POOLRAT backdoor on macOS.

Bangladesh Bank SWIFT Heist (2016)

APT38 attempted to steal $951 million from the Bangladesh Bank's account at the Federal Reserve Bank of New York by injecting fraudulent SWIFT transfer messages. A spelling error in one transfer request ("fandation" instead of "foundation") triggered scrutiny that limited actual losses to $81 million, which was routed through Philippine casinos. The operation demonstrated DPRK's willingness and ability to target the global financial infrastructure. The attack involved months of reconnaissance, custom SWIFT manipulation malware (NESTEGG, DYEPACK), and knowledge of bank clearing processes. It spurred a global overhaul of SWIFT security controls.

Ronin Network/Axie Infinity Hack (2022)

In March 2022, Lazarus Group stole approximately $625 million in Ethereum and USDC from the Ronin Network, a blockchain bridge supporting the Axie Infinity game. The attack exploited compromised private keys of validator nodes, obtained through a social engineering campaign involving a fake job offer sent to a senior Sky Mavis engineer via LinkedIn. The FBI attributed the theft to Lazarus Group and Treasury's OFAC sanctioned the associated wallet addresses.

TTP Evolution

DPRK cyber operations have undergone significant evolution:

  • Cryptocurrency Specialization: From traditional banking (SWIFT) to exchanges, DeFi protocols, bridges and hot wallets. Since 2025 the largest thefts have targeted off-chain infrastructure around the asset (wallet interface code at Bybit, RPC nodes at KelpDAO, backend signing systems at Bitget) instead of smart contract flaws [10][22][23].
  • Fewer, Larger Thefts: Chainalysis recorded a record total in 2025 from 74% fewer known attacks [11].
  • Long-Duration Social Engineering: The Drift operation involved about six months of in-person and online relationship building, including a real deposit of over $1 million to build credibility [21].
  • Social Engineering via Professional Networks: Fake recruiter and fake interview lures remain the primary initial access vector for both espionage and financial operations [24][26].
  • ClickFix and Fake Meetings: Kimsuky and BlueNoroff both adopted ClickFix. BlueNoroff pairs it with fake video meetings built from stolen webcam footage and AI-generated imagery [29][32].
  • Supply Chain Attacks: Progression from cascading vendor compromise (3CX) to hijacking maintainer accounts of widely used open-source packages (axios) and compromising regional software vendors to reach their customers [17][27].
  • Blockchain-Hosted Payloads: EtherHiding places payloads in smart contracts, which resists takedown [25].
  • Zero-Day Use: Lazarus exploited a Windows kernel driver zero-day in 2026 to deploy its FudModule rootkit [26].
  • Mobile Pivot for Credential Theft: Kimsuky's QR-code phishing moves the victim to an unmanaged device and ends in session token replay [31].
  • macOS Targeting: Continued development of macOS payloads, reflecting their prevalence among cryptocurrency developers. The Bybit chain began on a developer's Mac [10].
  • AI-Assisted Operations: Documented use of AI for face swapping on identity documents, voice changing, text-to-speech and translation in IT-worker and interview fraud [13][24].
  • Insider Threat Model: The IT worker scheme obtains legitimate authorized access, and is now also used to enable theft from cryptocurrency firms [11][12].
  • Rapid Laundering: TRM Labs observed Drift proceeds bridged within hours at a pace exceeding the Bybit laundering [19].

Infrastructure Patterns

  • VPN services and commercial proxy networks for operator anonymity; Astrill VPN recurs in vendor attribution [17]
  • Compromised web servers used as C2 relays, including PHP webshells on legitimate sites [26]
  • GitHub, Bitbucket and other code repositories for malware delivery via fake projects [24]
  • Malicious npm packages and hijacked legitimate packages for supply chain delivery [17][24]
  • Public blockchains (BNB Smart Chain, Ethereum) as payload hosting [25]
  • Legitimate cloud services as C2, including Microsoft Graph/OneDrive and Google Drive [26][27]
  • Typo-squatted Zoom, Teams and npm lookalike domains [28][29]
  • Use of legitimate communication platforms (Telegram, Slack, Discord) for victim contact and exfiltration
  • Cross-chain swap services, bridges, mixers and Chinese-language guarantee services for laundering [11]
  • Laptop farms at facilitators' residences in the United States and, since 2026, Japan, plus facilitator-managed VPS [12][24]
  • VoIP numbers and virtual phone services for synthetic identity support

Tooling

ToolTypeAssociated ActorsNotes
AppleJeusCryptocurrency trojanCitrine Sleet (UNC4736), LazarusTrojanized crypto trading apps targeting macOS and Windows
HOPLIGHTBackdoorLazarusCustom tunneling tool for proxy communications
BLINDINGCAN/DTrackRATLazarus, AndarielBlindingcan seen again in 2026 Medusa-linked intrusions [33]
TAXHAUL / COLDCAT / POOLRATLoader, downloader, macOS backdoorUNC47363CX compromise; SIMPLESEA was later determined by Mandiant to be POOLRAT [8]
BeaverTailInfostealerContagious Interview (WaterPlum)JavaScript stealer delivered in npm packages and repositories
InvisibleFerretBackdoorContagious Interview (WaterPlum)Python backdoor deployed alongside BeaverTail
OtterCookie / OtterCandyRAT and stealerContagious Interview (WaterPlum)JavaScript-based; OtterCandy combines OtterCookie with RATatouille features [24]
StoatWaffleModular loader/RATContagious Interview (WaterPlum)Node.js; abuses VS Code project configuration for auto-run [24]
JADESNOWDownloaderUNC5342Fetches payloads from smart contracts (EtherHiding) [25]
WAVESHAPER.V2 / SILKBELLBackdoor and dropperUNC1069 (Sapphire Sleet)Delivered through the axios compromise; Windows, macOS, Linux [17]
MISTPENDownloaderLazarusIn-memory; retrieves modules via Microsoft Graph API [26]
TroyBackdoorLazarusNew modular backdoor seen in 2026 Dream Job wave [26]
FudModuleKernel rootkitLazarusv3.1 exploited CVE-2026-68820; tampers with EDR and Smart App Control [26]
ComebackerBackdoor/loaderLazarusUsed in Medusa-linked intrusions [33]
GomirBackdoorKimsukyNew variants used against South Korean groupware vendors [27]
BabySharkScript-based malwareKimsukyDelivered through ClickFix lures in 2025 [32]
FastCashATM malwareAPT38Intercepts ISO 8583 transactions to authorize fraudulent cash withdrawals
ELECTRICFISHTunnelingLazarusCustom tunneling/proxy tool for maintaining covert communications
KANDYKORNmacOS backdoorBlueNoroffFull-featured macOS RAT targeting crypto developers
RandomQuery/FlowerPowerReconnaissanceKimsukyInformation collection tools deployed via spear-phishing

Intelligence Gaps

  • Attribution of 2026 thefts: Drift, KelpDAO and Bitget attributions rest on victim, vendor and blockchain-analytics assessments. No government attribution was found for any of them as of 2026-09-29. Some press reporting gives a higher Bitget figure (about $387 million) than the $351.6 million reported by Bitget and TRM Labs; this was not reconciled.
  • MSMT report detail: The October 2025 MSMT report was confirmed through the joint statement only; the full report could not be retrieved, so its figures are not cited here.
  • npm attribution: Amazon's medium-confidence attribution of the debug, chalk and typo-crypto compromises to Sapphire Sleet is not corroborated by another vendor [28].
  • Ransomware relationship: Whether Lazarus-linked activity in Medusa and other ransomware intrusions reflects tasking, moonlighting, tool sharing or access brokering is unknown [33][34].
  • Full IT worker infiltration scope: The true number of DPRK IT workers employed at foreign companies and the extent of their access is unknown. Revenue estimates range from $250 million to nearly $800 million a year.
  • Cryptocurrency laundering networks: The network of OTC brokers and conversion services is only partially mapped.
  • Revenue allocation: How stolen funds flow to weapons programs, leadership and operational reinvestment is poorly characterized.
  • Organizational structure: The relationship between RGB units and the 313 General Bureau of the Munitions Industry Department, and how vendor cluster names map to either, is not settled in open sources.
  • Zero-day capability: Lazarus used a Windows zero-day in 2026 [26], but whether such exploits are developed internally or acquired is unclear.
  • AI tool adoption: Identity fraud uses are documented. Reports of Kimsuky building local LLM environments and of AI-assisted exploit development were seen in secondary reporting but not verified against a primary source in this refresh.
  • Unverified leads: Reports of a Linux backdoor in trojanized HAProxy builds at South Korean organizations, DPRK-linked malicious Terraform providers and Go modules, and ScarCruft and Andariel activity in 2026 were not reviewed; those actor entries are unchanged from the seed text.

Live enrichment

When CrowdStrike Falcon Intelligence credentials are configured ($CROWDSTRIKE_CLIENT_ID), pull live vendor intelligence to keep this cell current and to answer specific actor questions:

  • Actor profile — /lookup-crowdstrike actor "Lazarus" / actor "Labyrinth Chollima" (origins, target countries/industries, motivations, capability, aliases)
  • TTPs — /lookup-crowdstrike ttps "Lazarus" → ATT&CK technique IDs; resolve against /mitre-attack
  • Latest reporting — /lookup-crowdstrike reports --actor "Stardust Chollima" --latest
  • Actor population — /lookup-crowdstrike actors --origin north-korea to enumerate DPRK-attributed adversaries CrowdStrike tracks (CrowdStrike uses the "Chollima" cryptonym for DPRK state-nexus actors)

Route through /threat-actor-profiling for a full structured profile. CrowdStrike report bodies are typically TLP:AMBER+ — cite report IDs internally, do not redistribute.

Sources & References

Shortened here. Read the whole file on GitHub.

Signals

GitHub stars
27
Forks
8
Last commit
Sep 2026
Advanced
Item type
skill
Key
dprk-cyber-espionage
Source
github.com/liberty91ltd/cti-skills