{"id":100309,"date":"2024-11-21T12:00:47","date_gmt":"2024-11-21T16:00:47","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=100309"},"modified":"2024-11-21T12:02:55","modified_gmt":"2024-11-21T16:02:55","slug":"south-korean-police-link-lazarus-group-to-hack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/south-korean-police-link-lazarus-group-to-hack\/","title":{"rendered":"South Korean Police Link Lazarus Group to $342M ETH Upbit Hack"},"content":{"rendered":"\n<p>South Korean police confirm that the North Korean hackers <a href=\"https:\/\/coinscreed.com\/staging\/lazarus-group-reportedly-behind-55m-coinex-hack.html\" target=\"_blank\" data-type=\"post\" data-id=\"59189\" rel=\"noreferrer noopener\">Lazarus group<\/a> and Andariel were responsible for the 342,000 ETH theft from Upbit in 2019.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack-1024x683.jpg\" alt=\"South Korean Police Link Lazarus Group to $342M ETH Upbit Hack\" class=\"wp-image-100312\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack-1024x683.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack-300x200.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack-768x512.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack-1536x1024.jpg 1536w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack-330x220.jpg 330w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack-420x280.jpg 420w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack-615x410.jpg 615w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack-860x573.jpg 860w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack-1320x880.jpg 1320w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack.jpg 1920w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>South Korean authorities have officially confirmed that the North Korean hacker groups Lazarus and Andariel were responsible for the 2019 theft of 342,000 Ethereum (ETH) from Upbit, the country\u2019s largest cryptocurrency exchange. <\/p>\n\n\n\n<p>This marks the first acknowledgment of North Korea's involvement in a domestic crypto exchange hack.<\/p>\n\n\n\n<p>The stolen ETH, valued at approximately 1.4 trillion won at current prices, was funneled through numerous exchanges worldwide. <\/p>\n\n\n\n<p>Despite the theft's magnitude, only a small portion of the funds has been recovered. Specifically, 4.8 Bitcoin was retrieved from a Swiss exchange.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Lazarus and Andariel Behind the Upbit Hack<\/h2>\n\n\n\n<p>South Korean police confirmed that the Lazarus and Andariel hacking groups orchestrated the <a href=\"https:\/\/coinscreed.com\/staging\/south-korea-confirms-nk-role-in-50m-upbit-hack.html\" target=\"_blank\" data-type=\"post\" data-id=\"100247\" rel=\"noreferrer noopener\">Upbit heist<\/a>, stealing 342,000 ETH, worth over 1.4 trillion won (about $1 billion). The stolen cryptocurrency was laundered through various methods. <\/p>\n\n\n\n<p>According to <a href=\"https:\/\/www.yna.co.kr\/view\/AKR20241121075800004?input=1195m\" target=\"_blank\" rel=\"noreferrer noopener\">a report by YNA.co<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, 57% of the ETH was exchanged for Bitcoin at a 2.5% discount on three exchange platforms believed to be controlled by North Korea. <\/p>\n\n\n\n<p>The remaining funds moved through 51 exchanges across 13 countries, including prominent platforms in the U.S. and China.<\/p>\n\n\n\n<p>South Korean investigators collaborated with the U.S. FBI and other international agencies to trace the stolen assets. Despite the widespread laundering, their efforts led to some recovery. <\/p>\n\n\n\n<p>After presenting evidence to Swiss authorities, officials successfully retrieved 4.8 Bitcoin, worth 600 million won, and returned it to Upbit, marking a rare success in recovering stolen cryptocurrency.<\/p>\n\n\n\n<p>This theft underscores North Korea's growing reliance on crypto hacks to support its activities. The Lazarus Group, in particular, has been linked to numerous high-profile cyberattacks targeting major crypto exchanges.<\/p>\n\n\n\n<p>The report also highlights the increasing prevalence of hacks and scams in the crypto space. For instance, the U.S. Department of Justice recently charged five hackers with stealing $6.3 million in digital assets.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">North Korea\u2019s History of Crypto Thefts and Global Impacts<\/h2>\n\n\n\n<p>The Lazarus Group, a state-sponsored cybercrime organization in North Korea, is known for conducting sophisticated cyberattacks on financial institutions and cryptocurrency exchanges worldwide. <\/p>\n\n\n\n<p>The group primarily focuses on high-value asset theft, particularly cryptocurrency.<\/p>\n\n\n\n<p>In a recent case, investigators connected Lazarus to a $238 million Bitcoin theft in August 2023. During this attack, stolen funds were moved across multiple platforms. <\/p>\n\n\n\n<p>Speculation about Lazarus\u2019s involvement grew as experts analyzed suspicious transactions tied to the incident.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>South Korean police confirm that the North Korean hackers Lazarus group and Andariel were responsible for the 342,000 ETH theft from Upbit in 2019. South Korean authorities have officially confirmed that the North Korean hacker groups Lazarus and Andariel were responsible for the 2019 theft of 342,000 Ethereum (ETH) from Upbit, the country\u2019s largest cryptocurrency [&hellip;]<\/p>\n","protected":false},"author":56,"featured_media":100312,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[9168,1712,2092],"class_list":["post-100309","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-lazarus-group","tag-south-korea","tag-upbit"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/11\/South-Korean-Police-Link-Lazarus-Group-to-342M-Upbit-ETH-Hack.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/100309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/56"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=100309"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/100309\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/100312"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=100309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=100309"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=100309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}