Nigerian Bank

#NigerianBank • 2016-07

🇳🇬 Nigeria

The Nigerian Bank incident is listed among DPRK-linked BangSwift financial operations in broad U.S. indictment and UN sanctions reporting that described North Korean RGB-associated actors, including activity associated in security reporting with Lazarus Group and APT38, conducting cyber-enabled bank theft, SWIFT-related fraud, laundering, and revenue-generation operations against financial institutions worldwide. The incident’s existing Bluenoroff attribution is preserved because the linked evidence frames the case within North Korean financial-theft activity and does not contradict that actor assignment.

Related Actors

Bluenoroff

Kaspersky

Bluenoroff is Kaspersky's name for a financially motivated unit within the broader Lazarus formation. Kaspersky introduced the designation publicly in 2017 while documenting bank intrusions connected to the 2016 Bangladesh Central Bank theft and other attacks on financial institutions and SWIFT-connected systems. The group used watering holes, backdoors, compromised infrastructure, and malware tailored to banking environments, with activity spanning multiple countries. By 2022, Kaspersky described a shift from banks and SWIFT servers toward cryptocurrency businesses as the group's principal source of illicit income. Operators created convincing cryptocurrency software companies and applications, delivered backdoored updates, and used malicious documents and social engineering to abuse trust. The reporting portrays Bluenoroff as able to draw on the larger formation's malware, exploits, and infrastructure while maintaining a distinct financial objective.

Lazarus Under The Hood
First seen: 2017-04 • Last seen: 2026-07

Related Reports

« Back