Security News > 2024 > February > North Korean hackers now launder stolen crypto via YoMix tumbler

The North Korean hacker collective Lazarus, infamous for having carried out numerous large-scale cryptocurrency heists over the years, has switched to using YoMix bitcoin mixer to launder stolen proceeds.
Some of the largest cryptocurrency theft operations Lazarus conducted in recent years include the March 2022 Ronin Network hack that yielded $625 million, the Harmony Horizon hack in June 2022 that resulted in losses of $100 million, and the July 2023 Alphapo heist from where the hackers pocketed $60 million worth of crypto.
From January 2017 until December 2023, North Korean hacking groups, including Lazarus, Kimsuky, and Andariel, have stolen an estimated $3 billion in crypto, according to a report from Recorded Future.
Chainalysis says YoMix is the latest service used by the North Korean threat actor.
"Based on Chainalysis data, roughly one-third of all YoMix inflows have come from wallets associated with crypto hacks," reads the report.
BleepingComputer has contacted YoMix with a request for a comment about the service being used by North Korean hackers to laundering illegal funds but we are yet to receive a response.
News URL
Related news
- North Korean hackers linked to $1.5 billion ByBit crypto heist (source)
- North Korean hackers adopt ClickFix attacks to target crypto firms (source)
- Hackers pose as employers to steal crypto, login credentials (source)
- North Korean Hackers Target Freelance Developers in Job Scam to Deploy Malware (source)
- OpenAI bans ChatGPT accounts used by North Korean hackers (source)
- North Korean Hackers Steal $1.5B in Cryptocurrency (source)
- Bybit Hack Traced to Safe{Wallet} Supply Chain Attack Exploited by North Korean Hackers (source)
- FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist (source)
- Safe{Wallet} Confirms North Korean TraderTraitor Hackers Stole $1.5 Billion in Bybit Heist (source)
- Microsoft: North Korean hackers join Qilin ransomware gang (source)