BitMEX uncovers holes in Lazarus Group’s operational security

Key Points

  • BitMEX security researchers uncovered significant operational security lapses in the Lazarus Group, a North Korean government-sponsored cybercrime network, including exposed IP addresses and access to a Supabase database.
  • A hacker likely revealed their true IP address, traced to Jiaxing, China, due to inconsistent VPN usage, highlighting amateur-level mistakes.
  • The analysis showed an asymmetry between the group’s low-skill social engineering teams and high-tech hackers, suggesting a splintered organization with varying threat capabilities.
  • Federal agencies and governments, including the FBI and leaders from the US, Japan, and South Korea, have issued warnings about Lazarus Group’s scams, such as phishing and fake job offers targeting crypto users.
  • The threat posed by the Lazarus Group may be discussed at the upcoming G7 Summit, with a focus on mitigating damage caused by DPRK-affiliated hackers.

Summary

BitMEX security researchers have exposed critical operational security flaws in the Lazarus Group, a North Korean state-sponsored cybercrime network, through a counter-operations probe. The investigation revealed IP addresses, a Supabase database, and tracking algorithms used by the group, with one hacker accidentally disclosing their location in Jiaxing, China, due to inconsistent VPN use. The report highlights a disparity between the group’s low-skill social engineering teams, which lure victims into downloading malware, and its sophisticated high-tech hackers, indicating a fragmented structure with varying threat levels. This comes amid a series of high-profile hacks and scams attributed to the Lazarus Group, prompting warnings from the FBI and governments of the US, Japan, and South Korea about phishing and fake job offer scams targeting crypto users. The issue’s severity has led to discussions about addressing the group’s threats at the upcoming G7 Summit.

cointelegraph
June 2, 2025
Crypto
Read article

Related news