Share this article

US Sanctions Three Alleged Crypto Hacking Groups From North Korea

The U.S. Treasury mentioned cryptocurrency thefts as one of the reasons for the action against the Lazarus Group, Bluenoroff and Andariel.

Updated Sep 13, 2021, 11:27 a.m. Published Sep 16, 2019, 8:00 a.m.
North Korea military parade

The U.S. has sanctioned three North Korean entities for cyber crimes, mentioning cryptocurrency thefts as one of the reasons for the action.

In a Sept. 13 announcement, the U.S. Department of the Treasury identified the Lazarus Group, Bluenoroff and Andariel as entities now on its the sanctions list, who are believed to be responsible for the theft of $571 million worth of cryptos from five exchanges in Asia in 2017 and 2018.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

The announcement comes just days after the North said that it would be holdings its second cryptocurrency-related conference, inviting the community to share information and do deals next February in Pyongyang.

The Treasury department said the stolen funds, including coins from cryptocurrency exchanges, are believed to have been used in the development of nuclear weapons and ballistic missiles.

As a result of the designation, all assets owned or controlled by any of the three entities are now blocked and must be reported to Office of Foreign Assets Control (OFAC). The announcement said that "U.S. persons," which broadly includes citizens, residents and companies incorporated in the U.S., are generally prohibited from dealing with the blocked entities. Anyone violating the sanctions could themselves be subject to designation by the Treasury.

Further, any financial institution in any country that deals with the blocked entities could lose their correspondent banking relationships with U.S. financial institutions, essentially locking them out of the dollar market.

Lazarus, which is the parent of the other two groups and also known as Apple Worm and Guardians of Peace, was involved in the WannaCry 2.0 ransomware attacks of 2017, the announcement added.

Bluenoroff, which came to the attention of security companies in 2014 and is sometimes known as APT38 or Stardust Chollima, has stolen funds from financial institutions, including $80 million from the Central Bank of Bangladesh, and has targeted cryptocurrency exchanges.

Andariel was first noticed by the internet security community in 2015 and is also attempting to engage in theft and sow confusion. It was said to be responsible for a 2016 hack into the personal computer of the South Korean Defense Minister.

All three groups are controlled by North Korea and related to the Reconnaissance General Bureau (RGB), according to the announcement.

A recent U.N. report alleges that the North has stolen $2 billion worth of crypto and fiat currencies in 35 separate attacks in 17 countries. South Korea's UPbit exchange may have been one of the targets, with the North using phishing attacks to gain control of the computers of customers.

North Korea image via Shutterstock

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Bitcoin’s Deep Correction Sets Stage for December Rebound, Says K33 Research

(Unsplash)

K33 Research says market fear is outweighing fundamentals as bitcoin nears key levels. December could offer an entry point for bold investors.

What to know:

  • K33 Research says bitcoin’s steep correction shows signs of bottoming, with December potentially marking a turning point.
  • The firm has argued that the market is overreacting to long-term risks while ignoring near-term signals of strength, like low leverage and solid support levels.
  • With likely policy shifts ahead and cautious positioning in futures, K33 sees more upside potential than risk of another major collapse.