teleo-codex/entities/internet-finance/lazarus-group.md
Teleo Agents 03e8eb9970
Some checks are pending
Sync Graph Data to teleo-app / sync (push) Waiting to run
rio: extract claims from 2026-04-05-coindesk-drift-north-korea-six-month-operation
- Source: inbox/queue/2026-04-05-coindesk-drift-north-korea-six-month-operation.md
- Domain: internet-finance
- Claims: 2, Entities: 2
- Enrichments: 0
- Extracted by: pipeline ingest (OpenRouter anthropic/claude-sonnet-4.5)

Pentagon-Agent: Rio <PIPELINE>
2026-04-07 10:20:47 +00:00

621 B

Lazarus Group

Type: organization
Status: active
Domain: internet-finance

Overview

North Korean state-sponsored hacking group responsible for billions in DeFi protocol thefts, demonstrating escalating sophistication from on-chain exploits to long-horizon social engineering operations.

Timeline

  • 2026-04-01 — Lazarus Group (attributed) executed $270-285M Drift Protocol exploit through six-month social engineering operation involving in-person meetings across multiple countries, $1M credibility deposit, and human coordination layer compromise rather than smart contract vulnerability