1 · Threat Actor Profile2 · Technical Analysis3 · Summary
TECHNICAL ANALYSIS CAMPAIGN INDEX

Lazarus Group — Campaigns Analyzed & Technical Reports

📅 2026-07-01 ⏱ 8 MIN READ ✍ SalahEldin Fikri (Mr_MaTriX) CRITICAL
An index of every Lazarus Group campaign covered in this research, with a short summary for each. Campaigns that received a full reverse-engineering / technical deep-dive link out to their own dedicated report; the rest link back to their write-up in the Threat Actor Profile.

1. Campaigns Analyzed

The table below lists every Lazarus Group campaign covered in this research, ordered most recent first. Only the 3CX Supply Chain Attack received a full malware reverse-engineering pass; it has its own dedicated technical report. Every other campaign links to its full write-up in the Threat Actor Profile.

YEAR CAMPAIGN PRIMARY VECTOR STATUS
2025 Bybit Cryptocurrency Heist Wallet transaction-signing compromise Stay tuned!
2025–Present Open-Source Package Supply Chain Campaigns Malicious npm / PyPI packages Stay tuned!
2024–Present Contagious Interview Campaign Fake recruiter social engineering Stay tuned!
2025 Mach-O Man macOS Malware Campaign Trojanized video-conferencing update (ClickFix) Stay tuned!
2024–Present Fake IT Worker Campaign Fraudulent remote employment / insider access Stay tuned!
2024 WazirX Cryptocurrency Exchange Attack Wallet infrastructure compromise Stay tuned!
2023 3CX Supply Chain Attack Signed build / CI/CD compromise ANALYZED - View Report
2018–Present Operation AppleJeus Trojanized cryptocurrency trading applications Stay tuned!
2017 WannaCry Ransomware EternalBlue (MS17-010) SMB exploitation Stay tuned!
2016 Bangladesh Bank Heist SWIFT messaging system fraud Stay tuned!
2014 Sony Pictures Attack Network intrusion & destructive malware Stay tuned!

2. Campaign Analysis Status

Lazarus Group has been linked to numerous high-profile cyber operations spanning espionage, financial theft, ransomware, software supply-chain compromises, and cryptocurrency attacks. The table below summarizes the major publicly attributed campaigns and their current analysis status within this research series.

Bybit Cryptocurrency Heist (2025)

Lazarus Group is attributed to the compromise of Bybit's wallet transaction-signing infrastructure, enabling fraudulent transfers totaling approximately $1.5 billion in cryptocurrency. The operation represents the largest publicly reported cryptocurrency theft to date. Analysis coming soon.

Open-Source Package Supply Chain Campaigns (2025–Present)

Lazarus distributed malicious npm and PyPI packages disguised as legitimate developer libraries to compromise software engineers, steal credentials, and collect cloud configuration files from development environments. Analysis coming soon.

Contagious Interview Campaign (2024–Present)

Fake recruiter personas lure software developers into downloading malicious coding challenges hosted on GitHub. Executing these projects installs malware capable of credential theft and remote access. Analysis coming soon.

Mach-O Man macOS Campaign (2025)

A macOS-focused campaign delivering the Python-based PyLangGhostRAT through trojanized collaboration software and ClickFix social engineering techniques, demonstrating Lazarus' continued expansion into Apple platforms. Analysis coming soon.

Fake IT Worker Campaign (2024–Present)

North Korean operatives use fabricated identities to obtain remote software engineering positions, leveraging insider access to steal sensitive information, generate revenue, and facilitate additional cyber operations. Analysis coming soon.

WazirX Cryptocurrency Exchange Attack (2024)

Approximately $235 million in cryptocurrency was stolen from the Indian exchange WazirX through the compromise of wallet infrastructure, with the stolen assets subsequently laundered through multiple blockchain services. Analysis coming soon.

3CX Supply Chain Attack (2023) — Fully Analyzed

Lazarus compromised the software supply chain of 3CX after first infiltrating a 3CX employee's workstation through the trojanized X_TRADER trading application. The attackers inserted malicious code into the 3CX build pipeline, producing digitally signed updates that distributed the trojanized 3CXDesktopApp.exe, ffmpeg.dll, d3dcompiler_47.dll, and the VEILEDSIGNAL backdoor to selected victims worldwide. This campaign has been fully reverse engineered in this research series.

→ Read the full technical analysis

Operation AppleJeus (2018–Present)

Trojanized cryptocurrency trading applications masquerade as legitimate investment software to deploy malware capable of persistence, credential theft, and direct cryptocurrency wallet compromise. Analysis coming soon.

WannaCry Ransomware (2017)

A self-propagating ransomware worm exploiting the EternalBlue SMB vulnerability spread across more than 150 countries, encrypting hundreds of thousands of systems and demanding cryptocurrency ransom payments. Analysis coming soon.

Bangladesh Bank Heist (2016)

Lazarus abused the SWIFT banking network to initiate fraudulent transfers totaling nearly $1 billion, successfully stealing approximately $81 million before the operation was disrupted. Analysis coming soon.

Sony Pictures Attack (2014)

One of Lazarus Group's earliest globally recognized operations, involving long-term network intrusion, large-scale data theft, destructive malware deployment, and the public release of sensitive internal corporate information. Analysis coming soon.

>_ secblog // all findings for educational & defensive use only