> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
BLUENOROFF
/actor/bluenoroff/ · 0 intel reports
BlueNoroff is a financially specialised sub-group of North Korea's Lazarus Group ecosystem, operating under the Reconnaissance General Bureau (RGB) with an explicit mandate to generate hard currency revenue for the Kim Jong-un regime through targeted attacks against financial institutions and cryptocurrency services globally. The group is responsible for some of the most financially devastating attacks ever conducted against the international banking system and represents North Korea's primary cryptocurrency theft operation.
BlueNoroff is the primary group behind North Korea's SWIFT-targeting campaigns , intrusions into the interbank messaging network that authorises international fund transfers. The group's most notorious SWIFT attack was the 2016 Bangladesh Bank heist, in which they stole $81 million by submitting fraudulent SWIFT transfer instructions to the Federal Reserve Bank of New York. Only a spelling error in one transfer instruction and an alert routing bank prevented the theft from reaching the full $951 million the group attempted to steal.
The group has evolved significantly toward cryptocurrency theft operations as digital assets have grown in market capitalisation and become an attractive target combining high value with the irreversibility and pseudonymity of blockchain transactions. BlueNoroff has targeted cryptocurrency exchanges, DeFi protocols, Web3 gaming platforms, and venture capital firms investing in the blockchain sector , using elaborate fake job offer social engineering campaigns to deliver malware to target employees.
A distinctive 2023-2024 campaign dubbed "Contagious Interview" saw BlueNoroff pose as recruiters from legitimate technology companies, inviting cryptocurrency and technology professionals to fake job interviews that required downloading a malicious "video conferencing" application , demonstrating the group's continuous innovation in social engineering to reach high-value targets protected by conventional phishing defences.
Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to BlueNoroff requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.