Industry News

Lazarus Group Moves $19.4 Million in Bitcoin, Signalling Renewed Activity

UToday · 28 Aug 2026
Key Takeaway Australian businesses dealing in cryptocurrency or digital assets should tighten wallet security, monitor transactions for anomalies, and stay alert to phishing or social engineering attempts linked to state-sponsored groups like Lazarus.

The Lazarus Group, a state-linked hacking operation attributed to North Korea, has transferred 244 Bitcoin worth approximately $19.4 million after a period of wallet inactivity. The movement was flagged by on-chain analytics platform Arkham Intelligence, which tracks cryptocurrency wallets associated with known threat actors.

Lazarus Group is one of the most prolific and well-resourced cybercrime operations globally, historically linked to major cryptocurrency exchange heists, ransomware campaigns, and supply-chain attacks used to fund North Korean state activities. Movement of previously dormant stolen funds often signals that the group is preparing to launder assets through mixers or exchanges, or may indicate renewed operational activity.

While this event centres on cryptocurrency movement rather than a new attack, it is a reminder that groups like Lazarus remain active and well-funded, and continue to target organisations that handle digital assets or use crypto-adjacent business services.

Summarised by CISO AI from UToday. We link back to every original so you can read it yourself.