North Korean Lazarus Group Registers US Shell Companies to Target Crypto Developers
The Lazarus Group, a cybercrime unit linked to North Korea’s Reconnaissance General Bureau, has breached US sanctions by establishing two shell companies—Blocknovas LLC and Softglide LLC—using falsified identities. A third entity, Angeloper Agency, remains unregistered. These fronts enabled malware attacks against cryptocurrency developers, marking a rare case of state-sponsored hackers legally incorporating US businesses to facilitate cyber operations.
Reuters reports the New Mexico and New York-registered firms were deployed as recruitment lures. The RGB’s involvement violates multiple UN Security Council resolutions restricting Pyongyang’s financial networks. This escalation demonstrates North Korea’s continued refinement of blockchain-focused threat vectors amid tightening global sanctions.