The Business of Cyber Security

Nation-State & APTs

On Feb 21, 2025, attackers drained roughly $1.5B in Ethereum from the crypto exchange Bybit — the largest single cryptocurrency theft in history. The FBI attributed it to the North Korean cluster it tracks as TraderTraitor (part of the Lazarus complex). The heist illustrates a defining feature of the modern threat economy: the erosion of the line between nation-state and criminal activity — a government stealing to fund its weapons program using techniques indistinguishable from organized crime. The state tier matters in two ways that point in opposite directions: financially-motivated state actors (chiefly North Korea) are now a top-tier criminal force, and strategically-motivated state actors (chiefly China) are pre-positioning inside critical infrastructure in ways that generate sovereign and OT-security demand. The sections below separate the two and map each to the deal flow it generates.

Wall Street research covering 1H 2026 added further examples of state-aligned activity: a China-aligned espionage group reported to have breached at least 70 government agencies and critical-infrastructure organizations across 37 countries over 2025–2026 to collect geopolitical intelligence; integrated cyber-and-physical operations around the Iran war (blackout-inducing electronic campaigns and retaliatory breaches on both sides) and the Venezuela conflict; and a February 2026 breach of the FBI in which non-public surveillance-related data was reported compromised.

Two kinds of state actor: money vs. position

The state tier splits cleanly by motive, and the motive determines both the technique and the defensive demand it creates:

The financially-motivated model is exemplified by North Korea (DPRK), which runs cyber as a revenue line for a sanctioned regime. In 2025 DPRK-linked actors stole ~$2.02B in cryptocurrency — a 51% increase year-over-year (up $681M from 2024's $1.3B) — and accounted for a record 76% of all crypto-service compromises, bringing the cumulative lower-bound estimate of DPRK crypto theft to roughly $6.75B. (Total crypto theft across all actors hit ~$3.4B in 2025, so DPRK alone was a majority of it.) The Bybit $1.5B heist drove the figure. Laundering runs through mixers, OTC brokers, chain-hopping, token swaps, DEXes, and bridge protocols. This is a state behaving as the world's most prolific crime syndicate.

The strategically-motivated model is exemplified by China's MSS-linked "Typhoon" groups, which seek position and intelligence, not money. Salt Typhoon (active since at least 2019, linked to China's Ministry of State Security and supported by contractors such as Sichuan Juxinhe Network Technology — sanctioned by the U.S. Treasury in Jan 2025) ran one of the most consequential espionage campaigns on record, compromising U.S. telecom providers and reportedly 200+ organizations across 80+ countries. Volt Typhoon is the more alarming twin: rather than steal data, it pre-positions for disruption, quietly establishing persistence inside U.S. power, water, and communications infrastructure (its 2023 compromise of Guam telecom systems via unpatched edge devices is the template) so that capability is in place should a conflict occur. Both rely on compromised valid credentials and "living-off-the-land" techniques — using built-in system tools rather than malware — to evade detection.

State cyber splits by motive — and each motive manufactures different demand Money (DPRK) vs. position/intelligence (China's Typhoons) FINANCIALLY MOTIVATED DPRK · Lazarus / TraderTraitor • 2025: ~$2.02B crypto stolen (+51% YoY) • Bybit ~$1.5B (Feb 2025) — largest ever • 76% of all service compromises • funds the sanctioned regime → crypto/exchange + supply-chain defense STRATEGICALLY MOTIVATED China MSS · Salt & Volt Typhoon • Salt: espionage; 200+ orgs, 80+ countries • Volt: pre-positioning in power/water/telecom • living-off-the-land · valid credentials • position for a future conflict → OT/ICS + telecom/network + sovereign Same toolkit (stolen creds, LOTL) — opposite goals. Each goal pulls a different defensive sub-segment. Source: Chainalysis (2026 Crime Report); FBI; CISA; U.S. Treasury; SecurityWeek; Congress.gov CRS. Exhibit: The Business of Cyber Security.
The DPRK column is a crime story that drives crypto-, exchange-, and supply-chain-security demand; the China column is a geopolitics story that drives OT/ICS, telecom/network, and sovereign-security demand. Reading which column is escalating tells you which deal cluster heats next.

The state-criminal blur

The clean "spies don't steal money, criminals don't serve states" distinction no longer holds, and the blur is itself a market force:

The consequence: defenders can no longer treat "nation-state" as a niche concern for governments and defense contractors. The same techniques — credential theft, edge-device exploitation, living-off-the-land — appear at every tier, which is why enterprise and even mid-market buyers now demand controls (ITDR, OT visibility, threat intelligence) once reserved for the public sector.

How the state tier maps to defensive demand and M&A

State activity (2025–26) Defensive demand it creates M&A / deal read
Volt Typhoon pre-positioning in OT/critical infra OT/ICS visibility, cyber-physical security The OT thesis — three independents acquired in six months (Mitsubishi–Nozomi, ServiceNow–Armis, Accenture–Dragos/runZero/NetRise); Claroty the last marquee independent (03h)
Salt Typhoon telecom/edge espionage Network/edge security, NDR, secure access Network/SASE consolidation (03d); telecom security
DPRK crypto theft + exchange compromise Crypto/exchange security, wallet/key mgmt, AML analytics Blockchain-security & on-chain-intel vendors; convergence with 24
DPRK fraudulent IT workers / insider access Identity verification, insider-threat, ITDR Identity & workforce-verification demand (03a)
Shared commodity supply chain (creds, IABs) Threat intelligence, dark-web monitoring, attribution TI consolidation; sovereign procurement of intel (14, 21)

Falsifiable bear case

The "nation-state threat is a durable demand engine" thesis is strong but has limits worth stating. (1) Sovereign demand is procurement-gated, not market-paced. Volt/Salt Typhoon may be terrifying, but the defensive spend they justify flows through slow government budgets, FedRAMP/CMMC gates, and prime-contractor channels (14) — meaning the M&A it generates is lumpy and politically timed, not a smooth growth curve. (2) DPRK demand is concentrated and possibly self-limiting. If crypto-tracing, exchange hardening, and stablecoin freezes keep improving, the laundering step gets harder and the theft economics deteriorate — and the defensive value pool (crypto-security) is narrow relative to the broad market. (3) Attribution and hype risk. "Nation-state" is the most over-claimed label in security marketing; vendors invoke APTs to justify premium pricing, and some "state-grade" demand is really ordinary enterprise spend wearing a geopolitical costume. The durable read is that the strategic (China/OT) column drives more enduring, broader demand than the financial (DPRK/crypto) column, because pre-positioning threatens every operator of physical infrastructure — not just exchanges.

/ angle

Volt Typhoon is the OT-security origination thesis. State pre-positioning inside power, water, and telecom is the single clearest demand driver behind the OT/ICS consolidation that took out three of the largest independents in six months (Mitsubishi–Nozomi, ServiceNow–Armis, Accenture–Dragos) and leaves Claroty as the last marquee independent in play (03h). When the geopolitical temperature rises, OT security re-rates — a buy-side and sell-side timing signal.

The state-criminal blur pulls "government-grade" controls into the commercial market. Capabilities once sold only to agencies (threat intelligence, ITDR, OT visibility) now have enterprise and mid-market demand, expanding the addressable buyer universe for vendors in those niches — and the relevance of sovereign/defense buyers as acquirers (14, 11b).


Sources: Chainalysis — 2025 crypto theft reaches $3.4B / DPRK $2.02B · The Hacker News — DPRK steal $2.02B in 2025 · CoinDesk — North Korea stole record $2B (Dec 18 2025) · SecurityWeek — Salt Typhoon hacked critical infrastructure globally · Congress.gov CRS — Salt Typhoon telecom hacks · CISA — China cyber threat overview


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.