Report: North Korea is launching Research Center 227, a cybersecurity research unit focused on AI-based hacking for stealing information and digital assets
The North Korean government is reportedly establishing a new hacking group within the intelligence agency Reconnaissance General Bureau (RGB). Bluesky: @myromanempire and @mnadeau X: @thegrugq and @lorenzofb Bluesky: @myromanempire : Investing to develop a unit to steal? Why steal when all you have to do is cut Trump a check? Michael Nadeau / @mnadeau : Not surprising but still concerning especially for the cryptocurrency community. NK is already adept at stealing crypto assets, and AI will make them more dangerous. [embedded post] X: Thaddeus E. Grugq / @thegrugq : Even Lazarus are losing their jobs to AI! Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: North Korea is reportedly launching a new cybersecurity research unit called Research Center 227, which will be housed within the intelligence agency Reconnaissance General Bureau (RGB), and will focus on AI-based hacking and stealing digital assets. https://techcrunch.com/...
Context & Ripple Effects
This reported unit extends a long-running RGB-linked cyber-revenue arc: earlier coverage described an expanding hacking operation oriented toward revenue generation and later documented crypto-focused attacks and fraud. It matters because the reported mandate explicitly joins information theft and digital-asset theft under an AI-based research function.
The target set is already familiar to defenders. Coverage of North Korean operatives posing as remote workers at US crypto firms and US efforts to disrupt laundering of stolen crypto shows that intrusion, access brokerage, and cash-out are interconnected rather than separate risks.
First-order effects
- Research Center 227 would give the Reconnaissance General Bureau a dedicated home for research aimed at AI-based hacking and theft, concentrating attention on both intelligence targets and digital assets.
- Crypto firms and other organizations handling sensitive information face a potentially broader threat surface if the reported unit turns AI research into more effective phishing, targeting, or operational support.
Second-order effects
- Security teams at exchanges and crypto employers may need to treat hiring controls, identity verification, and transaction-monitoring as connected defenses, not merely separate fraud and cybersecurity functions.
- Efforts to block laundering become more consequential: constraining cash-out can reduce the value of successful theft even when intrusion attempts continue.
Third-order effects
- If state-linked actors increasingly organize AI work around cyber operations, defensive advantage will depend less on securing individual systems alone and more on coordinating identity, software-security, and financial-crime controls.
- The pattern points toward cyber-enabled asset theft becoming a persistent state-capacity issue, with pressure for tighter cooperation between technology platforms, crypto businesses, and public authorities.
The trend: AI is becoming another layer in state-linked cyber operations, reinforcing the convergence of espionage, digital-asset theft, and financial disruption.