Inside Lazarus Group's Social Engineering Playbook Behind the Ronin Heist
North Korean operatives are increasingly turning their attention to decentralized finance, and the fallout from one of crypto's biggest heists is proving it.
The March attack on Ronin Network still stands as the largest cryptocurrency theft on record, yet it initially drew less public attention than the previous record-holder, Poly Network. That changed when the FBI announced it had attributed the theft to the Lazarus Group, a hacking collective backed by the North Korean state.

A day before this piece was published, the US Cybersecurity and Infrastructure Security Agency (CISA) released an advisory detailing the group's tactics, identifying it also as Advanced Persistent Threat 38. The agency wrote that North Korean state-backed operators "use a full array of tactics and techniques to exploit computer networks of interest, acquire sensitive cryptocurrency-intellectual property, and gain financial assets." The scale of the group's activity raises an open question about how many other incidents covered in rekt's archive may trace back to Pyongyang.
01A history predating crypto
Lazarus, and in particular its finance-oriented BlueNoroff unit, has a track record stretching back years, linked to the 2014 Sony Pictures breach, the 2016 Bangladesh Bank theft — in which more than $100 million was moved out of the Federal Reserve Bank of New York via SWIFT — and the 2017 WannaCry ransomware outbreak.
Within crypto specifically, the group has historically gone after centralized exchanges such as Kucoin, Liquid.com, NiceHash, and Bithumb, typically using social engineering to extract private keys. Lately, though, its focus has shifted toward DeFi targets.
Phishing is already a familiar hazard across DeFi and NFT communities, where both newcomers and experienced users get targeted through Discord and Telegram. In 2020, Nexus Mutual's Hugh Karp described losing $8 million this way, and just last month DeFiance Capital's Arthur Cheong lost roughly $1.7 million in a similar attack.
02How the validator set fell
Ronin's case went further — the entire network's security was undermined, partly because of an unusually small validator set. More than $600 million was drained from the network's bridge after attackers obtained five of the nine validator signatures required to approve transactions.
Four of those signatures belonged to a single entity, Sky Mavis, which likely made the network an attractive phishing target from the start. The fifth signature came through a separate channel: a long-standing but still-active arrangement that let Axie DAO sign on Sky Mavis's behalf to help manage network load. That backdoor gave Lazarus the opening it needed to reach a majority.
03The social engineering toolkit
Cybersecurity firm Kaspersky has documented just how refined BlueNoroff's approach to social engineering has become, noting: "If there's one thing BlueNoroff has been very good at, it's the abuse of trust."
Kaspersky's research describes an attack chain built around a malicious document distributed through Google Drive. Other methods the group has used include browser-in-the-browser (BitB) attacks, exploiting comment features in Google Docs, and building an entirely fake wallet application to trick victims. A more extensive collection of examples and screenshots is compiled in a thread by researcher Taylor Monahan.
Regardless of the specific method, success hinges on reducing suspicion by understanding the target organization in granular detail. Kaspersky's write-up elaborates: "The goal of the infiltration team is to build a map of interactions between individuals and understand possible topics of interest. This lets them mount high-quality social engineering attacks that look like totally normal interactions. A document sent from one colleague to another on a topic, which is currently being discussed, is unlikely to trigger any suspicion. BlueNoroff compromises companies through precise identification of the necessary people and the topics they are discussing at a given time."
The CISA advisory frames its purpose as supplying "information on tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to stakeholders in the blockchain technology and cryptocurrency industry to help them identify and mitigate cyber threats against cryptocurrency." It outlines a set of malicious applications sent to employees via spearphishing, disguised as "trading or price prediction tools."
According to the report, observed payloads include updated macOS and Windows variants of Manuscrypt, a custom remote access trojan capable of collecting system data, executing arbitrary commands, and fetching additional payloads (related tooling is described in CISA's earlier COPPERHEDGE analysis). The advisory notes that post-compromise activity is customized to each victim's environment, and in some cases has been completed within a week of initial intrusion. The document also lists indicators of compromise and mitigation steps, stressing that "a cybersecurity aware workforce is one of the best defenses against social engineering techniques like phishing."
Both Kaspersky and Cheong have urged crypto organizations to adopt basic protective measures: multisig wallets, hardware-based two-factor authentication, and dedicated devices reserved solely for crypto transactions.
04Tracing the money
With hacking activity in the space showing no sign of easing, blockchain forensics firms like Chainalysis are seeing rising demand for their services. Erin Plante, the firm's Senior Director of Investigations, offered this assessment: "The attribution of Lazarus to the Ronin attack underlines two trends in hacking. The first is the productivity of DPRK-affiliated threat actors and their exploitation of cryptocurrency. This is a national security concern considering they have stolen billions of dollars' worth of crypto and the UN has connected this activity to funding their nuclear program. The second trend is the need for better security for DeFi protocols. Almost 97% of all cryptocurrency stolen in the first three months of 2022 has been taken from DeFi protocols, up from 72% in 2021 and just 30% in 2020."
Chainalysis published a broader report in January cataloguing North Korea-linked crypto thefts dating back to 2017. Factoring in the roughly $600 million taken from Ronin, 2022 has already surpassed the DPRK's total haul from all of last year — and the year isn't even half over.
05Laundering at scale
The report also sheds light on how the funds get cleaned. Alongside a somewhat unusual reliance on centralized exchanges — a channel normally avoided given KYC requirements — Chainalysis found that the group is leaning more heavily on mixing services, apparently growing more cautious as crypto activity draws greater mainstream scrutiny.

The typical laundering sequence Chainalysis describes runs as follows: ERC-20 tokens and altcoins get swapped into Ether through a decentralized exchange; that Ether passes through a mixer; the mixed Ether is then swapped for Bitcoin, again via DEX; the Bitcoin itself gets mixed; the mixed Bitcoin is consolidated into fresh wallets; and finally it's routed to deposit addresses at Asia-based crypto-to-fiat exchanges, which serve as potential cash-out points.
Chainalysis also floated the possibility that Lazarus sits on stolen funds deliberately, waiting for law enforcement scrutiny to fade — a pattern consistent with the group's growing list of exploits. That patience can span years: per the report, "of DPRK's total holdings, roughly $35 million came from attacks in 2020 and 2021. By contrast, more than $55 million came from attacks carried out in 2016 — meaning that DPRK has massive unlaundered balances as much as six years old."
This time, however, the pace looks different. The Ronin proceeds are already moving quickly through laundering channels, with Elliptic estimating that around $107 million has already been processed.
06Tornado Cash under scrutiny
While the use of centralized exchanges is atypical for DeFi-related laundering, the group's continued preference for Tornado Cash is unsurprising. Given the intense law enforcement focus on the case and the central role mixers play in obscuring stolen funds, it was only a matter of time before Tornado Cash itself came under pressure.
On the Thursday following the CISA report, Tornado Cash — a privacy tool with its own following among hackers — issued a statement confirming that addresses on an on-chain sanctions list maintained by Chainalysis — which includes the Ronin exploiter's address — would be blocked from using the dapp's front end.
Since the underlying smart contracts remain immutable, however, restricting front-end access is unlikely to stop anyone capable of executing a heist of this scale, state-sponsored or not. Whether that move amounts to genuine compliance or simply a gesture meant to placate regulators remains an open question — and as scrutiny intensifies, how far governments will go to rein in this parallel financial system is still very much unresolved.
Get new scam files the moment we publish them — usually 2–3 emails a week.