Nation-State & APTs
On Feb 21, 2025, attackers drained roughly $1.5B in Ethereum from the crypto exchange Bybit — the largest single cryptocurrency theft in history. The FBI attributed it to the North Korean cluster it tracks as TraderTraitor (part of the Lazarus complex). The heist illustrates a defining feature of the modern threat economy: the erosion of the line between nation-state and criminal activity — a government stealing to fund its weapons program using techniques indistinguishable from organized crime. The state tier matters in two ways that point in opposite directions: financially-motivated state actors (chiefly North Korea) are now a top-tier criminal force, and strategically-motivated state actors (chiefly China) are pre-positioning inside critical infrastructure in ways that generate sovereign and OT-security demand. The sections below separate the two and map each to the deal flow it generates.
Wall Street research covering 1H 2026 added further examples of state-aligned activity: a China-aligned espionage group reported to have breached at least 70 government agencies and critical-infrastructure organizations across 37 countries over 2025–2026 to collect geopolitical intelligence; integrated cyber-and-physical operations around the Iran war (blackout-inducing electronic campaigns and retaliatory breaches on both sides) and the Venezuela conflict; and a February 2026 breach of the FBI in which non-public surveillance-related data was reported compromised.
Two kinds of state actor: money vs. position
The state tier splits cleanly by motive, and the motive determines both the technique and the defensive demand it creates:
The financially-motivated model is exemplified by North Korea (DPRK), which runs cyber as a revenue line for a sanctioned regime. In 2025 DPRK-linked actors stole ~$2.02B in cryptocurrency — a 51% increase year-over-year (up $681M from 2024's $1.3B) — and accounted for a record 76% of all crypto-service compromises, bringing the cumulative lower-bound estimate of DPRK crypto theft to roughly $6.75B. (Total crypto theft across all actors hit ~$3.4B in 2025, so DPRK alone was a majority of it.) The Bybit $1.5B heist drove the figure. Laundering runs through mixers, OTC brokers, chain-hopping, token swaps, DEXes, and bridge protocols. This is a state behaving as the world's most prolific crime syndicate.
The strategically-motivated model is exemplified by China's MSS-linked "Typhoon" groups, which seek position and intelligence, not money. Salt Typhoon (active since at least 2019, linked to China's Ministry of State Security and supported by contractors such as Sichuan Juxinhe Network Technology — sanctioned by the U.S. Treasury in Jan 2025) ran one of the most consequential espionage campaigns on record, compromising U.S. telecom providers and reportedly 200+ organizations across 80+ countries. Volt Typhoon is the more alarming twin: rather than steal data, it pre-positions for disruption, quietly establishing persistence inside U.S. power, water, and communications infrastructure (its 2023 compromise of Guam telecom systems via unpatched edge devices is the template) so that capability is in place should a conflict occur. Both rely on compromised valid credentials and "living-off-the-land" techniques — using built-in system tools rather than malware — to evade detection.
The state-criminal blur
The clean "spies don't steal money, criminals don't serve states" distinction no longer holds, and the blur is itself a market force:
- States are the criminals (DPRK). North Korea's theft is state policy executed with criminal tradecraft, often laundering through the same mixers and OTC desks used by ransomware crews (15a). It also runs the fraudulent-IT-worker scheme — placing operatives in remote engineering jobs at Western firms to earn wages and plant access — blending insider threat, fraud, and espionage.
- States shelter and direct criminals (Russia). Many of the most prolific RaaS operators sit in jurisdictions that won't extradite and that tolerate — or quietly steer — attacks against adversaries, giving the state deniable offensive reach via the criminal ecosystem.
- States use the criminal supply chain. APTs increasingly buy from the same initial-access brokers and use the same commodity infostealers as criminals, making attribution harder and the access economy a shared resource across the whole threat spectrum.
The consequence: defenders can no longer treat "nation-state" as a niche concern for governments and defense contractors. The same techniques — credential theft, edge-device exploitation, living-off-the-land — appear at every tier, which is why enterprise and even mid-market buyers now demand controls (ITDR, OT visibility, threat intelligence) once reserved for the public sector.
How the state tier maps to defensive demand and M&A
| State activity (2025–26) | Defensive demand it creates | M&A / deal read |
|---|---|---|
| Volt Typhoon pre-positioning in OT/critical infra | OT/ICS visibility, cyber-physical security | The OT thesis — three independents acquired in six months (Mitsubishi–Nozomi, ServiceNow–Armis, Accenture–Dragos/runZero/NetRise); Claroty the last marquee independent (03h) |
| Salt Typhoon telecom/edge espionage | Network/edge security, NDR, secure access | Network/SASE consolidation (03d); telecom security |
| DPRK crypto theft + exchange compromise | Crypto/exchange security, wallet/key mgmt, AML analytics | Blockchain-security & on-chain-intel vendors; convergence with 24 |
| DPRK fraudulent IT workers / insider access | Identity verification, insider-threat, ITDR | Identity & workforce-verification demand (03a) |
| Shared commodity supply chain (creds, IABs) | Threat intelligence, dark-web monitoring, attribution | TI consolidation; sovereign procurement of intel (14, 21) |
Falsifiable bear case
The "nation-state threat is a durable demand engine" thesis is strong but has limits worth stating. (1) Sovereign demand is procurement-gated, not market-paced. Volt/Salt Typhoon may be terrifying, but the defensive spend they justify flows through slow government budgets, FedRAMP/CMMC gates, and prime-contractor channels (14) — meaning the M&A it generates is lumpy and politically timed, not a smooth growth curve. (2) DPRK demand is concentrated and possibly self-limiting. If crypto-tracing, exchange hardening, and stablecoin freezes keep improving, the laundering step gets harder and the theft economics deteriorate — and the defensive value pool (crypto-security) is narrow relative to the broad market. (3) Attribution and hype risk. "Nation-state" is the most over-claimed label in security marketing; vendors invoke APTs to justify premium pricing, and some "state-grade" demand is really ordinary enterprise spend wearing a geopolitical costume. The durable read is that the strategic (China/OT) column drives more enduring, broader demand than the financial (DPRK/crypto) column, because pre-positioning threatens every operator of physical infrastructure — not just exchanges.
/ angle
→ Volt Typhoon is the OT-security origination thesis. State pre-positioning inside power, water, and telecom is the single clearest demand driver behind the OT/ICS consolidation that took out three of the largest independents in six months (Mitsubishi–Nozomi, ServiceNow–Armis, Accenture–Dragos) and leaves Claroty as the last marquee independent in play (03h). When the geopolitical temperature rises, OT security re-rates — a buy-side and sell-side timing signal.
→ The state-criminal blur pulls "government-grade" controls into the commercial market. Capabilities once sold only to agencies (threat intelligence, ITDR, OT visibility) now have enterprise and mid-market demand, expanding the addressable buyer universe for vendors in those niches — and the relevance of sovereign/defense buyers as acquirers (14, 11b).
Sources: Chainalysis — 2025 crypto theft reaches $3.4B / DPRK $2.02B · The Hacker News — DPRK steal $2.02B in 2025 · CoinDesk — North Korea stole record $2B (Dec 18 2025) · SecurityWeek — Salt Typhoon hacked critical infrastructure globally · Congress.gov CRS — Salt Typhoon telecom hacks · CISA — China cyber threat overview
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.