1 min read
LockBit Operators Utilizing New AV-Bypass Tool
Published 07/08/2024
3 min read
Cyber Florida SOCAP Team
:
Updated on September 15, 2026
Originally Published April 9, 2025
Financial Sector, Crypto Space, ByBit, ByBit affiliates, and ByBit customers.
On February 21, 2025, Bybit, a major cryptocurrency exchange, experienced a security breach that resulted in the loss of $1.5 billion worth of Ethereum. This incident is the largest digital heist in cryptocurrency history. Bybit is currently collaborating with experts to trace the stolen assets. They have launched a recovery bounty program, offering up to 10% of the recovered amount to individuals who help retrieve the stolen crypto.
The Lazarus Group, a well-known hacking collective believed to be based in North Korea, has claimed responsibility for the attack. This group is notorious for orchestrating high-profile cyberattacks, particularly targeting financial institutions. In this instance, the attackers infiltrated a developer's computer associated with the Gnosis Safe wallet, a widely used multi-signature wallet designed for secure management of cryptocurrency assets. Gnosis Safe operates by requiring multiple private key approvals to authorize transactions, providing an added layer of security to prevent unauthorized transfers.
However, the Lazarus Group managed to manipulate the Safe user interface (UI) specifically used for Bybit transactions. By injecting malicious JavaScript into the UI, they created the illusion that Bybit was authorizing a legitimate transaction. This allowed the attackers to bypass security protocols and facilitate the unauthorized transfer of funds, effectively masking their illicit actions as legitimate business operations. This attack highlights the vulnerabilities associated with software development environments and the potential for targeted manipulation of trusted tools like the Gnosis Safe.
The Lazarus group, also known as APT38, has been active since at least 2009. The Lazarus group was reportedly responsible for the November 2014 attack against Sony Pictures Entertainment as a part of a campaign named Operation Blockbuster by Novetta. The group has been correlated to other campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.
In 2017, the Lazarus group was reportedly responsible for the creation of the malware used in the 2017 WannaCry 2.0 global ransomware attack; the 2016 theft of $81 million from Bangladesh bank; and numerous other attacks or intrusions on the entertainment, financial services, defense, technology, and virtual currency industries, academia, and electric utilities.
The largest cryptocurrency heist attributed to Lazarus prior was in 2024 with the $308 million attack on Japan-based exchange DMM Bitcoin; the compromise of the Japanese cryptocurrency wallet software firm swiftly led to the company's collapse and was largely known as the single largest crypto theft until now.
Initial Access via Supply Chain Compromise (T1071.001): Attackers gained access by compromising a developer's machine associated with Safe , the platform used by Bybit for managing multi-signature wallets.
User Interface Manipulation (T1071.001): They injected malicious JavaScript into the Safe interface, altering transaction details to mislead wallet signers into approving unauthorized transactions.
Transaction Manipulation (T1071.001): By modifying the appearance and details of transactions, the attackers ensured that the signers unknowingly authorized the transfer of funds to addresses under their control.
Command and Control (T1071.001): The use of malicious JavaScript indicates a command-and-control mechanism to deliver and execute payloads on compromised systems.
Some recommendations we can offer to ensure your cryptocurrency is secure and mitigate the risks of this hack occurring:
The list of addresses associated with the Bybit hack is still continuously being updated, and the blocklist can be found here.
Bybit Confirms Security Integrity Amid Safe Incident – No Compromise in Infrastructure. Bybit Press. (2025, February 26). https://www.bybit.com/en/press/post/bybit-confirms-security-integrity-amid-safe-wallet-incident-no-compromise-in-infrastructure-blt9986889e919da8d2
Greig, J. (2024, December 25). FBI attributes largest crypto hack of 2024 to North Korea's TraderTraitor. Cyber Security News | The Record. https://therecord.media/fbi-largest-crypto-hack-2024-tradertraitor
Internet Crime Complaint Center (IC3) | North Korea responsible for $1.5 billion bybit hack. (2025, February 26). https://www.ic3.gov/PSA/2025/PSA250226
North Korean Regime-Backed Programmer Charged With Conspiracy to. (2025, February 6). https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and
Team, C. (2025, February 27). Leveraging transparency for collaboration in the wake of Record-Breaking Bybit theft [UPDATED 2/27/25]. Chainalysis. https://www.chainalysis.com/blog/bybit-exchange-hack-february-2025-crypto-security-dprk/
The Bybit hack: following North Korea's largest exploit | TRM Insights. (n.d.). https://www.trmlabs.com/post/the-bybit-hack-following-north-koreas-largest-exploit
Threat Advisory created by the Cyber Florida Security Operations Center.
Contributing Security Analysts: Nahyan Jamil and Jason Doan
1 min read
Published 07/08/2024
1 min read
Originally published: 04/07/2025 I. Targeted Entities Energy Sector Healthcare Sector Transportation Sector Financial Services Critical...
1 min read
Originally Published April 1, 2026