Bluenoroff is Kaspersky's name for a financially motivated unit within the broader Lazarus formation. Kaspersky introduced the designation publicly in 2017 while documenting bank intrusions connected to the 2016 Bangladesh Central Bank theft and other attacks on financial institutions and SWIFT-connected systems. The group used watering holes, backdoors, compromised infrastructure, and malware tailored to banking environments, with activity spanning multiple countries. By 2022, Kaspersky described a shift from banks and SWIFT servers toward cryptocurrency businesses as the group's principal source of illicit income. Operators created convincing cryptocurrency software companies and applications, delivered backdoored updates, and used malicious documents and social engineering to abuse trust. The reporting portrays Bluenoroff as able to draw on the larger formation's malware, exploits, and infrastructure while maintaining a distinct financial objective.
Bitrefill
#Bitrefill • 2026-03
Bitrefill experienced a cyberattack beginning around early March 2026, which was traced back to a compromised employee device that exposed internal credentials. Using this access, attackers infiltrated the company’s systems and were able to drain funds from its hot wallets while also abusing its gift card infrastructure. The breach led to unauthorized transactions and unusual purchasing activity, which eventually triggered detection and forced the company to shut down parts of its system to contain the incident.
In addition to financial losses, the attackers accessed tens of thousands of purchase records, including customer emails, crypto wallet addresses, and some encrypted data. Bitrefill has not disclosed the exact amount stolen but confirmed both monetary damage and operational disruption. The company noted that the attack showed patterns similar to those used by the Lazarus Group, although it stopped short of making a definitive attribution.
-
2
Related Reports
-
1
Affected Countries
-
5
Months Since