The U.S. Department of Justice (DoJ) has charged three North Koreans with stealing $1.3 billion in cash and cryptocurrency through cyberattacks on banks, the entertainment industry, cryptocurrency companies and more. The defendants are North Korean state hackers and members of units of the Reconnaissance General Bureau (RGB), a North Korean military intelligence agency that has been involved in cybercrime operations. These North Korean military hacking units are known by many names, including the Lazarus Group and APT (Advanced Persistent Threat) 38.

According to the DoJ, the three North Koreans are involved in a broad criminal conspiracy to conduct a series of devastating cyberattacks, to steal more than $1.3 billion in cryptocurrency from financial institutions and companies, to create and deploy multiple malicious cryptocurrency applications, and to develop a blockchain.
The three defendants are Jon Chang Hyok, Kim Il and Park Jin Hyok, while Park was also indicted in September 2018 for participating in a broad, multi-year conspiracy aimed at hacking computers and committing fraud.

The Lazarus Group, monitored by the US as HIDDEN COBRA, targets high-profile organizations such as Sony Pictures Entertainment, as well as many banks worldwide.
As BleepingComputer, the hacking campaign allowed hackers to steal hundreds of millions of US dollars – approximately $140 million – by breaching the Bangladesh Bank, the Bank of Chile, and the Taiwan International Bank.

North Korean-backed hackers have been accused of numerous hacking activities, including the following:
- Cyberattacks on the entertainment industry: The devastating cyberattack on Sony Pictures Entertainment in November 2014 – in retaliation for “The Interview,” a film depicting a fictional assassination of the DPRK leader in December 2014 – as well as a 2015 hack of Mammoth Screen, which produced a fictional series featuring a British nuclear scientist held captive by the DPRK.
- Cyberattacks on banks: Attempts from 2015 to 2019 to steal more than $1.2 billion from banks in Vietnam, Bangladesh, Taiwan, Mexico, Malta and Africa, by breaching the banks' computer networks and sending "fraudulent" SWIFT (Society for Worldwide Interbank Financial Telecommunication) messages.
- ATM cyberattacks: ATM thefts, including the October 2018 theft of $6.1 million from the Pakistani Islamic bank “BankIslami Pakistan Limited.”
- Creation of the devastating WannaCry 2.0 ransomware in May 2017, extortion and attempted extortion of victim companies from 2017 to 2020 by stealing sensitive data and developing other ransomware.
- Creation and deployment of malicious cryptocurrency applications : Development of multiple malicious cryptocurrency applications from March 2018 to at least September 2020 – including Celas Trade Pro, WorldBit-Bot, iCryptoFx, Union Crypto Trader, Kupay Wallet, CoinGo Trade, Dorusio, CryptoNeuro Trader, and Ants2Whale – that would provide North Korean hackers with a backdoor into victims’ computers
- Targeting cryptocurrency companies and stealing cryptocurrency: Targeting hundreds of cryptocurrency companies and stealing tens of millions of dollars worth of cryptocurrency, including $75 million from a Slovenian cryptocurrency company in December 2017, $24.9 million from an Indonesian cryptocurrency company in September 2018, and $11.8 million from a financial services company in New York in August 2020, where hackers used the malicious CryptoNeuro Trader app as a backdoor.
- Spear-Phishing Campaigns: Multiple spear-phishing from March 2016 to February 2020, which targeted US employees working at, among others, energy companies, aerospace companies, technology companies, the US Department of State, and the US Department of Defense.

The indictment alleges that the goal of the North Korean hackers was to “advance the strategic and economic interests of the DPRK government and its leader, Kim Jong Un, by causing damage, as well as stealing data and money from organizations around the world.”.
The United Nations estimated in 2019 that North Korea has made up to $2 billion from at least 35 cyberattacks targeting banks and cryptocurrency exchanges in more than a dozen countries.
Another United Nations report from 2019 said that DPRK-backed hackers were believed to be behind $571 million in economic losses.
These profits allow the North Korean regime to continue investing in its ballistic missile and nuclear programs, according to the DoJ.
Also in 2019, the U.S. Treasury Department imposed sanctions on three North Korean hacking groups (Lazarus Group, Bluenoroff, and Andariel) engaged in funneling stolen financial assets to the North Korean government.
