Lazarus Group Bitrefill Cyberattack Crypto Threat
ID: a99dfbb9-e763-5051-a947-ebb5e66f7b88
STIX ID: report--a99dfbb9-e763-5051-a947-ebb5e66f7b88
Feed Name: Cyble Blog
Threat Score
Bitrefill disclosed a March 1, 2026 intrusion attributed to the Lazarus Group (North Korea) in which attackers gained access via a compromised employee laptop and a legacy credential, escalated privileges, probed for high-value crypto assets, drained hot wallets, and accessed ~18,500 purchase records; the report outlines attacker TTPs, attribution indicators, and Bitrefill's remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
