TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Recorded Future Blog

Lazarus Doesn't Need AGI

2026-04-28 · Read original ↗

ATT&CK techniques detected

3 predictions
T1657Financial Theft
93%
"- linked cryptocurrency theft reached roughly $ 3 billion through 2023. the multilateral sanctions monitoring team ( successor to the un panel of experts after russia ’ s 2024 veto ) has since done the harder primary work. msmt ’ s october 2025 report documents $ 2. 8 billion sto…"
T1078Valid Accounts
77%
"##use. a legitimately credentialed employee at a third - party vendor uses their access for unauthorized purposes. this is the mythos story. the credentials and access are real, though the intent is variable. defenses ( easy to say, hard to do well ) : telemetry, behavioral monit…"
T1078Valid Accounts
48%
"the same operator - hours, more successful intrusions, and more stolen $ $ $ per operator. bybit is an easy example. the fbi attributed approximately $ 1. 5 billion in stolen virtual assets to tradertraitor in february 2025. the intrusion chain ran months of patient targeting aga…"

Summary

Explore the 2026 Claude Mythos breach, supply chain risks, and the $2B+ crypto theft pipeline.