Threat Picture
Latest Cybersecurity News

Park Jin Hyok: The Paper Trail Behind the Lazarus Charges

Investigators followed an email trail from a developer in China to allegations involving Sony, a central bank and WannaCry.
By Charles Joseph · Updated
Share
Share
Copy URL

Park Jin Hyok is the only face the world has ever put on the Lazarus Group. His FBI wanted poster shows a young man in a dark jacket, and behind that photograph sits a North Korean hacking machine that's stolen billions.

The US charged him in 2018 with a conspiracy that ran from the 2014 attack on Sony Pictures to the $81 million Bangladesh Bank heist to WannaCry, the ransomware that shut down British hospitals. The FBI called the damage "virtually unparalleled."

The strange part is how they found him. Not through the malware, but through a résumé, a Gmail address and a photo of a quiet developer-for-hire in a Chinese port city.

Park Jin Hyok at a Glance

  • A résumé recovered by the FBI lists his birthday as August 15, 1984, a degree from Kim Chaek University of Technology in Pyongyang, and a job at Chosun Expo from 2002 as an "online game developer."
  • Chosun Expo began as a joint North-South e-commerce venture and ended up a front company earning money for a North Korean hacking organization known as Lab 110.
  • From late 2010 or early 2011 until late 2013 or early 2014 he worked in Dalian, China, writing legitimate software for paying clients, then returned home shortly before the Sony attack.
  • In November 2014 the "Guardians of Peace" wiped thousands of Sony Pictures computers and leaked its films and emails to punish the comedy The Interview.
  • In February 2016 the same crew sent fake SWIFT orders from Bangladesh Bank for close to $1 billion and got $81 million out through Philippine casinos.
  • In May 2017 WannaCry hit more than 150 countries, including 80 of the 236 trusts in Britain's National Health Service.
  • A 179-page FBI complaint filed on June 8, 2018, and unsealed on September 6, charged Park with two conspiracy counts, and the Treasury sanctioned him the same day.
  • A 2021 indictment added two more North Korean officers and expanded the alleged haul to more than $1.3 billion, much of it cryptocurrency.
  • He's never been arrested and is last known to be in North Korea.
Sponsored

The Life of Park Jin Hyok

Park's Early Years

Almost everything known about Park's early life comes from a single document: a résumé attached to a business email that the FBI later obtained. It gives his date of birth as August 15, 1984, lists Kim Chaek University of Technology, one of Pyongyang's most prestigious schools, and describes a developer fluent in English and Chinese who coded in Visual C++, Java, PHP and Flash.

The FBI's own poster is vaguer. Park, it notes, "has reported dates of birth in 1984 and 1981."

Whichever is right, he was still a teenager when, according to that résumé, he joined Chosun Expo in 2002.

A Front Company Called Chosun Expo

Chosun Expo, also known as Korea Expo Joint Venture, had an unlikely origin. According to the FBI's affidavit, it started as a joint venture between North and South Korea to run a Korean e-commerce and lottery website, and when the South withdrew, the North kept the business.

What it became was a currency machine. The company sold software, freelance development and gambling products, and some of its programmers were stationed abroad to earn fees from foreign clients, several of whom knew exactly who they were hiring.

The affidavit says Chosun Expo was affiliated with a government hacking organization "sometimes known as 'Lab 110,'" and that it generated money for it. A North Korean website bearing the company's name described it as the country's first internet company.

Sponsored

The Programmer in Dalian

In late 2010 or early 2011, Park was sent to Dalian, the Chinese port city in Liaoning province, which borders North Korea. He joined a team of North Korean programmers doing contract work, and on January 10, 2011, his department head emailed a client to say that a new developer, "Pak Jin Hek," would be replacing a colleague on the team.

That email carried the résumé, and the photo.

Park used several email accounts in his own name during his years in China. One of them, [email protected], would turn out to be the thread that unraveled everything.

The Man Called Kim Hyon Woo

The Lazarus hackers ran their operations through a separate set of accounts registered to a persona named "Kim Hyon Woo," which the FBI concluded was a cover name rather than a person.

One of those operational addresses was [email protected]. It shared a naming pattern with Park's real account, had been accessed from the same computers, and in turn was tied to accounts used to spear-phish Sony Pictures and Bangladesh Bank.

By 2014, the affidavit says, Park appears to have returned to North Korea, and the accounts he'd used in Dalian were now being logged into from North Korean IP addresses. The hacking crews might change their names, but they didn't change their habits.

The Interview and the Guardians of Peace

On Friday, November 21, 2014, senior Sony Pictures executives got an email from someone calling himself "Frank David." It demanded "monetary compensations" for unspecified damage and was signed "From God'sApstls."

Three days later, employees logging in found a threatening image on their screens and the words "Hacked By #GOP." The malware behind it was a wiper, and it rendered thousands of Sony computers inoperable while the attackers dumped unreleased films and internal financial data onto the internet.

The target was The Interview, a comedy about a plot to assassinate Kim Jong-un that Sony was due to release on Christmas Day. The same accounts also sent malware to employees of AMC Theatres and to Mammoth Screen, a British production company developing a series about a nuclear scientist held captive in North Korea.

Sponsored

The Billion-Dollar Bank Job

In February 2016 the crew went after Bangladesh Bank, the country's central bank. Having worked their way into the terminals that spoke to the SWIFT interbank network, they sent authenticated transfer orders that came close to $1 billion.

Most were blocked, but $81 million reached accounts in the Philippines that'd been opened the previous May under fictitious names. From there it was laundered through a remittance business and casino junkets, and most of it has never been recovered.

Another $20 million bound for Sri Lanka was stopped by the receiving bank. The FBI called the theft the largest successful cyber-heist from a financial institution to date.

WannaCry

The affidavit traces WannaCry through three versions. An early build appeared around February 2017, another in March and April, and on May 12, 2017, "Version 2" began spreading on its own across the planet.

Britain's National Health Service was the most visible casualty: 80 of its 236 trusts were affected, at least 37 were actually infected, and hospitals canceled appointments while they pulled systems offline. Computers in more than 150 countries were hit.

What tied it to Park's crew was code. The FBI's analysts found the same data tables, encryption keys and command domains inside an early WannaCry sample, the Sony wiper and the Bangladesh malware.

Wanted

The FBI filed its complaint under seal on June 8, 2018, and the Justice Department unsealed it on September 6, charging Park with conspiracy to commit computer fraud and conspiracy to commit wire fraud. The same day the Treasury sanctioned him and Chosun Expo under an executive order aimed at North Korea's cyber operations.

In February 2021 a broader indictment named Park alongside two other officers of North Korea's Reconnaissance General Bureau, Jon Chang Hyok and Kim Il. It accused the three of stealing and extorting more than $1.3 billion from banks, ATM networks and cryptocurrency exchanges, and of building fake crypto apps to break into them.

Park was 36 by then, according to the Justice Department. He's never been in a courtroom.

Sponsored

Where Park Is Now

The FBI's poster says he's a North Korean citizen "last known to be in North Korea," and the State Department has offered up to $5 million for information on North Korean cyber operations.

The organization he's accused of serving hasn't slowed down. In February 2025 the FBI blamed North Korea for the theft of about $1.5 billion in cryptocurrency from the exchange Bybit, the largest crypto heist on record.

Park remains the one name attached to all of it.

Park Jin Hyok: The Face of a Faceless Army

Most cyberattacks end with a shrug about attribution. Park's case is the opposite: an indictment that reads like a detective novel, built from reused email accounts and a résumé with a photo.

It'll probably never produce a trial. North Korea doesn't hand over its hackers, and the men on the FBI's posters are soldiers of a state that depends on their income.

But it put a name and a face to an alleged member of the shadowy "Lazarus Group": someone with a birthday, a university and a boss. That's a kind of exposure no regime can patch.

QUOTE:

"Amateurs hack systems, professionals hack people."