The BitMex Crypto Exchange security team has discovered gaps in the field of operating security Lazarus Group, sponsored by the government of the cybercrime network in North Korea (DPRK), in accordance with the probe prevention of the organization, which revealed IP addresses, database and tracking algorithms used by the group’s plant.
Safety researchers say that there is a high probability that at least one hacker accidentally revealed his real IP address, which showed the actual location of the hacker in Jiaxing in China.
In addition, Bitmex researchers claim that they were also able to access the Suppabase database instance, platforms for basic implementation of databases with elementary application interfaces used by a hacking group.
According to reportThe analysis emphasized the asymmetry between social engineering teams in a group designed to guide nothing suspected victims to download malware and interaction with sophisticated code exploits developed by advanced technologies.
This asymmetry signals that the hacker organization associated with North Korea has divided into separate subgroups, with different levels of threat possibilities cooperating in order to deceive users, said Bitmex team.
The report is a consequence of a number of raucous hacking incidents, social engineering fraud and infiltration of blockchain and companies related to the Lazarus Group and other agents related to North Korea.
Related: The northern Korean spy slips, reveals ties in a false interview
Federal law enforcement agencies and governments check the alarm in the Lazarus group
Federal law enforcement agencies and governments around the world are increasingly investigating the activities of hackers related to DPRK, sounding alarm in a number of common fraud strategies used by these threatening entities.
In September 2024, the Federal United States Investigative Bureau (FBI) issued a warning about the fraud of social engineering committed by the group supported by the DPRK, including phishing tests focused on cryptographic users with false employment offers.
https://www.youtube.com/watch?v=ndv0rfeetq
The governments of Japan, the USA and South Korea repeated the FBI warning in January 2025 and characterized the hacking activity as a threat to the financial system.
The recent Bloomberg report suggested that world leaders could discuss the threat of the Lazarus hacker group at the next G7 summit and strategies of damages caused by the organization related to the DPRK.
Warehouse: Lazarus’ favorite exploit was revealed – analysis of cryptographic hacks