logo

Lazarus Group Bitrefill Cyberattack Crypto Threat

ID: a99dfbb9-e763-5051-a947-ebb5e66f7b88

STIX ID: report--a99dfbb9-e763-5051-a947-ebb5e66f7b88

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2026-03-20

Date Updated: 2026-07-17

...
...

Bitrefill disclosed a March 1, 2026 intrusion attributed to the Lazarus Group (North Korea) in which attackers gained access via a compromised employee laptop and a legacy credential, escalated privileges, probed for high-value crypto assets, drained hot wallets, and accessed ~18,500 purchase records; the report outlines attacker TTPs, attribution indicators, and Bitrefill's remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.