{"id":18517,"date":"2025-12-01T04:34:36","date_gmt":"2025-12-01T03:34:36","guid":{"rendered":"https:\/\/wsj-crypto.com\/?p=18517"},"modified":"2025-12-01T04:34:36","modified_gmt":"2025-12-01T03:34:36","slug":"north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge","status":"publish","type":"post","link":"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/","title":{"rendered":"&#8220;North Korea&#8217;s Lazarus Group: The Cyber Villains Leading the Phishing Charge&#8221;"},"content":{"rendered":"<p> &#8220;`html<br \/>\n<\/p>\n<div data-v-0ccfa88e=\"\">\n<p>Have you heard about the Lazarus Group? These North Korean state-backed hackers have been busy making headlines for their creative and sneaky tactics! Over the past year, they\u2019ve mainly used spear phishing attacks to steal money, and South Korean cybersecurity company AhnLab reports that they were the most talked-about group in post-hack analyses.<\/p>\n<p>Spear phishing is a favorite tool for shady players like Lazarus. They send fake emails that appear to be harmless \u2014 think lecture invites or job interview requests. AhnLab analysts <a href=\"https:\/\/www.ahnlab.com\/ko\/contents\/content-center\/36017?utm\" rel=\"noopener nofollow\" target=\"_blank\">shared<\/a> insights in their Cyber Threat Trends &amp; 2026 Security Outlook report on November 26, 2025.<\/p>\n<figure><figcaption style=\"text-align: center;\"><em>Spear phishing is a more advanced kind of phishing, requiring hackers to do their homework first. Source: <\/em><a href=\"https:\/\/www.kaspersky.com\/resource-center\/definitions\/spear-phishing\" rel=\"nofollow\" target=\"https:\/\/www.kaspersky.com\/resource-center\/definitions\/spear-phishing\" title=\"https:\/\/www.kaspersky.com\/resource-center\/definitions\/spear-phishing\"><em>Kaspersky<\/em><\/a><em>\u00a0<\/em><\/figcaption><\/figure>\n<p>The <a href=\"https:\/\/cointelegraph.com\/people\/top-people-in-crypto-and-blockchain-2023\/lazarus-group\/\">Lazarus Group is believed to be behind<\/a> many notorious attacks in various sectors, particularly in crypto. They\u2019re suspected of taking part in the massive <a href=\"https:\/\/cointelegraph.com\/news\/bybit-exchange-hacked\">$1.4 billion hack on Bybit<\/a> on February 21, as well as the recent <a href=\"https:\/\/cointelegraph.com\/news\/upbit-freezes-deposits-and-withdrawals-after-36m-hot-wallet-breach\">$30 million exploit involving Upbit<\/a> last Thursday.<\/p>\n<h2>Protect Yourself from Spear Phishing<\/h2>\n<p>Spear phishing attacks are a precise form of phishing <a href=\"https:\/\/www.kaspersky.com\/resource-center\/definitions\/spear-phishing\" rel=\"nofollow\" target=\"https:\/\/www.kaspersky.com\/resource-center\/definitions\/spear-phishing\" title=\"https:\/\/www.kaspersky.com\/resource-center\/definitions\/spear-phishing\">where<\/a> hackers take time to gather info about their targets, pretending to be someone you trust in order to steal your personal information or compromise your systems.<\/p>\n<p>To keep yourself safe, cybersecurity experts at Kaspersky recommend some simple steps: use a VPN to secure your online activities, avoid sharing too many personal details online, double-check the source of suspicious emails or messages through a different communication channel, and activate multifactor or biometric authentication whenever you can.<\/p>\n<h2>The Need for a \u2018Multi-Layered Defense\u2019 Against Hackers<\/h2>\n<p data-ct-non-breakable=\"undefined\">The Lazarus Group isn\u2019t picky; they\u2019ve launched attacks in the crypto space, finance, IT, and defense sectors. AhnLab points out that they were the most frequently cited group in analyses between October 2024 and September 2025 \u2014 with 31 mentions!<\/p>\n<p>Following close behind was another North Korean group, Kimsuky, with 27 mentions, and TA-RedAnt having 17.<\/p>\n<p data-ct-non-breakable=\"undefined\">AhnLab suggests that businesses need a \u201cmulti-layered defense system\u201d to fend off attacks. This means conducting regular security audits, keeping software updated with patches, and training team members on various attack strategies.<\/p>\n<p data-ct-non-breakable=\"undefined\"><em><strong>Related: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/news\/zhao-google-government-backed-hackers\"><em><strong>CZ\u2019s Google account targeted by \u2018government-backed\u2019 hackers<\/strong><\/em><\/a><\/p>\n<p data-ct-non-breakable=\"undefined\">For individual safety, AhnLab advises adopting multifactor authentication, ensuring security software is always up-to-date, avoiding unverified links and attachments, and only downloading from trusted sources.<\/p>\n<h2>AI is Helping Bad Actors Get Smarter<\/h2>\n<p data-ct-non-breakable=\"undefined\">As we head into 2026, AhnLab warns that new tech like artificial intelligence will only make hackers more efficient and their attacks even trickier.<\/p>\n<p><template data-ct-widget=\"buzzsprout\" data-buzzsprout-podcast-id=\"2040516\" data-buzzsprout-episode-id=\"17674691\"\/><\/p>\n<p data-ct-non-breakable=\"undefined\">Hackers are already using AI to craft realistic phishing emails and websites that are hard to identify. AhnLab believes AI can help create various modified codes precisely to dodge detection, making spear phishing even more effective through deepfakes.<\/p>\n<blockquote><p>\u201cWith the increasing use of AI technology, deepfake attacks, like those that steal sensitive information, are expected to evolve to a point where they are near impossible to spot. It\u2019s crucial to be vigilant and safeguard your data!\u201d<\/p><\/blockquote>\n<p data-ct-non-breakable=\"undefined\"><em><strong>Magazine: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/magazine\/2026-pragmatic-privacy-crypto-canton-zcash-ethereum-foundation\/\"><em><strong>2026 is the year of pragmatic privacy in crypto: Canton, Zcash and more<\/strong><\/em><\/a><\/p>\n<p><template data-name=\"subscription_form\" data-type=\"defi_newsletter\" label=\"Subscription Form: DeFi Newsletter\"\/>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/spear-phishing-north-korean-hackers-top-tactic-how-to-stay-safe?utm_source=rss_feed&#038;utm_medium=rss&#038;utm_campaign=rss_partner_inbound\">Source link <\/a><br \/>\n&#8220;`<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;`html Have you heard about the Lazarus Group? These North Korean state-backed hackers have been busy making headlines for their creative and sneaky tactics! Over the past year, they\u2019ve mainly used spear phishing attacks to steal money, and South Korean cybersecurity company AhnLab reports that they were the most talked-about group in post-hack analyses. Spear<\/p>\n","protected":false},"author":3,"featured_media":18518,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22],"tags":[4429],"class_list":{"0":"post-18517","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-bitcoin","8":"tag-gptreturn-a-list-of-comma-separated-tags-from-this-title-north-korea-lazarus-group-tops-cyber-threats-with-spear-phishing-attacks-gpt"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>&quot;North Korea&#039;s Lazarus Group: The Cyber Villains Leading the Phishing Charge&quot; - WSJ-Crypto<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/\" \/>\n<meta property=\"og:locale\" content=\"it_IT\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"&quot;North Korea&#039;s Lazarus Group: The Cyber Villains Leading the Phishing Charge&quot; - WSJ-Crypto\" \/>\n<meta property=\"og:description\" content=\"&#8220;`html Have you heard about the Lazarus Group? These North Korean state-backed hackers have been busy making headlines for their creative and sneaky tactics! Over the past year, they\u2019ve mainly used spear phishing attacks to steal money, and South Korean cybersecurity company AhnLab reports that they were the most talked-about group in post-hack analyses. Spear\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/\" \/>\n<meta property=\"og:site_name\" content=\"WSJ-Crypto\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-01T03:34:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/12\/0195dc1d-21f7-75e1-b1ae-836b4ae2906c.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"799\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"wsjcrypto\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Scritto da\" \/>\n\t<meta name=\"twitter:data1\" content=\"wsjcrypto\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tempo di lettura stimato\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minuti\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/\",\"url\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/\",\"name\":\"\\\"North Korea's Lazarus Group: The Cyber Villains Leading the Phishing Charge\\\" - WSJ-Crypto\",\"isPartOf\":{\"@id\":\"https:\/\/wsj-crypto.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/12\/0195dc1d-21f7-75e1-b1ae-836b4ae2906c.jpeg\",\"datePublished\":\"2025-12-01T03:34:36+00:00\",\"author\":{\"@id\":\"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7\"},\"breadcrumb\":{\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/#breadcrumb\"},\"inLanguage\":\"it-IT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/#primaryimage\",\"url\":\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/12\/0195dc1d-21f7-75e1-b1ae-836b4ae2906c.jpeg\",\"contentUrl\":\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/12\/0195dc1d-21f7-75e1-b1ae-836b4ae2906c.jpeg\",\"width\":1200,\"height\":799,\"caption\":\"North Korea Lazarus Group Tops Cyber Threats with Spear Phishing Attacks\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/wsj-crypto.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"&#8220;North Korea&#8217;s Lazarus Group: The Cyber Villains Leading the Phishing Charge&#8221;\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/wsj-crypto.com\/#website\",\"url\":\"https:\/\/wsj-crypto.com\/\",\"name\":\"WSJ-Crypto\",\"description\":\"Just Another Crypto News Website\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/wsj-crypto.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"it-IT\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7\",\"name\":\"wsjcrypto\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\/\/wsj-crypto.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g\",\"caption\":\"wsjcrypto\"},\"url\":\"https:\/\/wsj-crypto.com\/index.php\/author\/wsjcrypto\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\"North Korea's Lazarus Group: The Cyber Villains Leading the Phishing Charge\" - WSJ-Crypto","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/","og_locale":"it_IT","og_type":"article","og_title":"\"North Korea's Lazarus Group: The Cyber Villains Leading the Phishing Charge\" - WSJ-Crypto","og_description":"&#8220;`html Have you heard about the Lazarus Group? These North Korean state-backed hackers have been busy making headlines for their creative and sneaky tactics! Over the past year, they\u2019ve mainly used spear phishing attacks to steal money, and South Korean cybersecurity company AhnLab reports that they were the most talked-about group in post-hack analyses. Spear","og_url":"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/","og_site_name":"WSJ-Crypto","article_published_time":"2025-12-01T03:34:36+00:00","og_image":[{"width":1200,"height":799,"url":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/12\/0195dc1d-21f7-75e1-b1ae-836b4ae2906c.jpeg","type":"image\/jpeg"}],"author":"wsjcrypto","twitter_card":"summary_large_image","twitter_misc":{"Scritto da":"wsjcrypto","Tempo di lettura stimato":"2 minuti"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/","url":"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/","name":"\"North Korea's Lazarus Group: The Cyber Villains Leading the Phishing Charge\" - WSJ-Crypto","isPartOf":{"@id":"https:\/\/wsj-crypto.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/#primaryimage"},"image":{"@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/#primaryimage"},"thumbnailUrl":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/12\/0195dc1d-21f7-75e1-b1ae-836b4ae2906c.jpeg","datePublished":"2025-12-01T03:34:36+00:00","author":{"@id":"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7"},"breadcrumb":{"@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/#breadcrumb"},"inLanguage":"it-IT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/"]}]},{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/#primaryimage","url":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/12\/0195dc1d-21f7-75e1-b1ae-836b4ae2906c.jpeg","contentUrl":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/12\/0195dc1d-21f7-75e1-b1ae-836b4ae2906c.jpeg","width":1200,"height":799,"caption":"North Korea Lazarus Group Tops Cyber Threats with Spear Phishing Attacks"},{"@type":"BreadcrumbList","@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/12\/01\/north-koreas-lazarus-group-the-cyber-villains-leading-the-phishing-charge\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wsj-crypto.com\/"},{"@type":"ListItem","position":2,"name":"&#8220;North Korea&#8217;s Lazarus Group: The Cyber Villains Leading the Phishing Charge&#8221;"}]},{"@type":"WebSite","@id":"https:\/\/wsj-crypto.com\/#website","url":"https:\/\/wsj-crypto.com\/","name":"WSJ-Crypto","description":"Just Another Crypto News Website","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wsj-crypto.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"it-IT"},{"@type":"Person","@id":"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7","name":"wsjcrypto","image":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/wsj-crypto.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g","caption":"wsjcrypto"},"url":"https:\/\/wsj-crypto.com\/index.php\/author\/wsjcrypto\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts\/18517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/comments?post=18517"}],"version-history":[{"count":2,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts\/18517\/revisions"}],"predecessor-version":[{"id":18520,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts\/18517\/revisions\/18520"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/media\/18518"}],"wp:attachment":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/media?parent=18517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/categories?post=18517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/tags?post=18517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}