Crypto market maker DWF Labs has allegedly suffered a $44 million cyberattack tied to North Korea's Lazarus Group, using the AppleJeus malware. The breach, which occurred in September 2022 but was only recently uncovered, involved the compromise of a specific wallet address (0x3d67fdE4B4F5077f79D3bb8Aaa903BF5e7642751) through a phishing-laced trading application.
Investigators reported that the attackers primarily stole USDC and USDT stablecoins, with the funds being drained over several hours on September 22, 2022, and one additional transaction the following day. The stolen assets were then laundered via the Ren Protocol bridge to Bitcoin and later obscured using the Mixero custodial Bitcoin mixer.
This incident is part of a broader pattern, with the Lazarus Group estimated to have stolen over $3 billion in digital assets over the past five years to fund North Korea's weapons programs. DWF Labs has not issued an official statement but has reportedly strengthened cybersecurity protocols, including wallet segregation and multi-signature custody, with no client losses reported.