HomeSecurityIs the Lazarus Group behind the hack of the crypto exchange Upbit?

Is the Lazarus Group behind the hack of crypto exchange Upbit?

South Korea is once again facing a wave of digital anxiety after a major cyberattack on cryptocurrency exchange Upbit resulted in the unauthorized outflow of 44.5 billion won (about $30.4 million) in digital assets . According to a report by Yonhap news agency , authorities are seriously considering the possibility that the attack came from the notorious North Korean cyber espionage group Lazarus Group .

Upbit

Research in full swing — The first indications

Government cybersecurity officials and police experts have already begun combing through Upbit's infrastructure, attempting to map out how the attack was carried out. According to sources cited by Yonhap, the modus operandi bears striking similarities to previous incidents involving Lazarus, which is directly linked to spy agency Pyongyang's.

See also: Hackers target telecommunications and media organizations

A government official, speaking on condition of anonymity, said that “the evidence points to a very familiar tactic that we have seen before from North Korean groups.” Although authorities are avoiding public statements until the technical analysis is complete, the direction of the investigation already appears to have been defined.

Lazarus' modus operandi — Why it's considered a top APT

The Lazarus Group has been one of the most dangerous and active players in cyberspace for years. The FBI has described the group as “one of the most advanced and persistent threats on the planet,” and its activities range from governments and military targets to banks, cryptocurrency exchanges, and even large corporations.

A major motivation behind these attacks is believed to be North Korea's need to finance its nuclear and ballistic missile programs while circumventing international sanctions. Cybercrime has become, in effect, part of the state's economic strategy.

See also: OpenAI: Data breach via third-party provider Mixpanel

The Upbit incident is reminiscent of the 2019, when approximately 58 billion won in cryptocurrency was lost — an event that was also linked to Lazarus at the time.

Is the Lazarus Group behind the hack of crypto exchange Upbit?

Reactions from Upbit and Dunamu

Dunamu , the company that operates Upbit, confirmed that it is in the process of investigating both the cause of the breach and the ultimate extent of the damage. A company spokesperson said laconically: “ We are in the process of fully analyzing the data to understand the scope of the asset outflow and how it occurred .”

The incident is all the more significant because it occurred just hours before the announcement that South Korean internet giant Naverwas acquiring Dunamu. The coincidence raises questions about whether the perpetrators chose the timing strategically.

Upbit in the spotlight – Why it is such an attractive target

Upbit is not just another exchange; it is the largest crypto exchange in South Korea, with millions of users and huge daily trading volumes. For international cybercrime groups, such a platform has the perfect balance: high liquidity, large reserves, and significant geopolitical value.

See also: Alleged hackers posted a zero-day exploit for iOS 26 on the Dark Web

Attacks of this kind, especially when linked to state-sponsored entities, are not only aimed at direct financial gain but also at disrupting the stability of exchanges and the broader cryptocurrency market.

Is the Lazarus Group behind the hack of crypto exchange Upbit?

The Day After — What It Means for South Korea and the Crypto Ecosystem

The incident highlights, once again, how fragile the digital asset ecosystem can be. South Korean authorities are expected to strengthen security regulations for crypto exchanges, while experts predict even stricter requirements regarding storage, authentication and transaction monitoring.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

For companies in the space, the message is clear: attacks are not a matter of "if," but "when" — and many times, the adversary can be an entire state apparatus.

Source: Reuters

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS