According to this warning, North Korean hackers are targeting us with this kind of attacks,
The North Korean "WaterPlum" cyber actor group (commonly referred to as “Contagious Interview”) conducts cyberattacks by infiltrating unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency. WaterPlum is victimizing individual IT professionals in Japan, the United States, Europe, and other countries.
So any form of cyber attack now originates from North Korea?
Someone please help me understand how people come up with such conclusions.
Is it a case of North Korea being a country full of the deadliest hackers around the world, or are their hackers just too stupid that hey cannot even cover their tracks, like, for example, mask their IP addresses?
I don't know if you have heard about the recent Bybit hack, but the exchange said they suspect that North Korea is behind.
Or maybe you can read the reports here, I'm not the one accusing them, and it has been in crypto space for many years. The big difference here is that the Lazarus group is state sponsored so they are sophisticated, but one mistake might reveal their true identity:
https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/North Korean hackers stole $2.02 billion in cryptocurrency in 2025, a 51% year-over-year increase, pushing their all-time total to $6.75 billion despite fewer attacks.
The DPRK is achieving larger thefts with fewer incidents, often by embedding IT workers inside crypto services or using sophisticated impersonation tactics targeting executives.
The DPRK shows clear preferences for Chinese-language money laundering services, bridge services, and mixing protocols, with a 45-day laundering cycle following major thefts.
Individual wallet compromises surged to 158,000 incidents affecting 80,000 unique victims in 2025, though total value stolen ($713M) decreased from 2024.
Despite increased Total Value Locked in DeFi, hack losses remained suppressed in 2024-2025, suggesting improved security practices are making a meaningful difference.
Or maybe this article might answer your question as how the investigators track it to North Korea:
https://www.trmlabs.com/resources/blog/the-bybit-hack-following-north-koreas-largest-exploitAlmost immediately following the ByBit hack, TRM identified and tagged the compromised addresses as “Hacked” or “Stolen Funds” and established a dedicated tracking entity labeled "Bybit Exploiter Feb 2025" to monitor the movement of the stolen assets in real time.
Through blockchain intelligence, TRM Labs confirmed that North Korean hackers were responsible for the breach, linking it to previous state-sponsored crypto heists. The evidence revealed clear overlaps between the wallets used in this operation and those associated with past North Korean thefts. On February 26, 2025, the FBI officially linked the heist to North Korea.