The table below lists every Lazarus Group campaign covered in this research, ordered most recent first. Only the 3CX Supply Chain Attack received a full malware reverse-engineering pass; it has its own dedicated technical report. Every other campaign links to its full write-up in the Threat Actor Profile.
| YEAR | CAMPAIGN | PRIMARY VECTOR | STATUS |
|---|---|---|---|
| 2025 | Bybit Cryptocurrency Heist | Wallet transaction-signing compromise | Stay tuned! |
| 2025–Present | Open-Source Package Supply Chain Campaigns | Malicious npm / PyPI packages | Stay tuned! |
| 2024–Present | Contagious Interview Campaign | Fake recruiter social engineering | Stay tuned! |
| 2025 | Mach-O Man macOS Malware Campaign | Trojanized video-conferencing update (ClickFix) | Stay tuned! |
| 2024–Present | Fake IT Worker Campaign | Fraudulent remote employment / insider access | Stay tuned! |
| 2024 | WazirX Cryptocurrency Exchange Attack | Wallet infrastructure compromise | Stay tuned! |
| 2023 | 3CX Supply Chain Attack | Signed build / CI/CD compromise | ANALYZED - View Report |
| 2018–Present | Operation AppleJeus | Trojanized cryptocurrency trading applications | Stay tuned! |
| 2017 | WannaCry Ransomware | EternalBlue (MS17-010) SMB exploitation | Stay tuned! |
| 2016 | Bangladesh Bank Heist | SWIFT messaging system fraud | Stay tuned! |
| 2014 | Sony Pictures Attack | Network intrusion & destructive malware | Stay tuned! |
Lazarus Group has been linked to numerous high-profile cyber operations spanning espionage, financial theft, ransomware, software supply-chain compromises, and cryptocurrency attacks. The table below summarizes the major publicly attributed campaigns and their current analysis status within this research series.
Lazarus Group is attributed to the compromise of Bybit's wallet transaction-signing infrastructure, enabling fraudulent transfers totaling approximately $1.5 billion in cryptocurrency. The operation represents the largest publicly reported cryptocurrency theft to date. Analysis coming soon.
Lazarus distributed malicious npm and PyPI packages disguised as legitimate developer libraries to compromise software engineers, steal credentials, and collect cloud configuration files from development environments. Analysis coming soon.
Fake recruiter personas lure software developers into downloading malicious coding challenges hosted on GitHub. Executing these projects installs malware capable of credential theft and remote access. Analysis coming soon.
A macOS-focused campaign delivering the Python-based PyLangGhostRAT through trojanized collaboration software and ClickFix social engineering techniques, demonstrating Lazarus' continued expansion into Apple platforms. Analysis coming soon.
North Korean operatives use fabricated identities to obtain remote software engineering positions, leveraging insider access to steal sensitive information, generate revenue, and facilitate additional cyber operations. Analysis coming soon.
Approximately $235 million in cryptocurrency was stolen from the Indian exchange WazirX through the compromise of wallet infrastructure, with the stolen assets subsequently laundered through multiple blockchain services. Analysis coming soon.
Lazarus compromised the software supply chain of 3CX after first infiltrating a
3CX employee's workstation through the trojanized X_TRADER trading application.
The attackers inserted malicious code into the 3CX build pipeline, producing
digitally signed updates that distributed the trojanized
3CXDesktopApp.exe, ffmpeg.dll,
d3dcompiler_47.dll, and the
VEILEDSIGNAL backdoor to selected victims worldwide.
This campaign has been fully reverse engineered in this research series.
→ Read the full technical analysis
Trojanized cryptocurrency trading applications masquerade as legitimate investment software to deploy malware capable of persistence, credential theft, and direct cryptocurrency wallet compromise. Analysis coming soon.
A self-propagating ransomware worm exploiting the EternalBlue SMB vulnerability spread across more than 150 countries, encrypting hundreds of thousands of systems and demanding cryptocurrency ransom payments. Analysis coming soon.
Lazarus abused the SWIFT banking network to initiate fraudulent transfers totaling nearly $1 billion, successfully stealing approximately $81 million before the operation was disrupted. Analysis coming soon.
One of Lazarus Group's earliest globally recognized operations, involving long-term network intrusion, large-scale data theft, destructive malware deployment, and the public release of sensitive internal corporate information. Analysis coming soon.