Threat actor
Lazarus Group
Last fetched
Lazarus Group is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 93 techniques and also known as 44 other names.
Also known as
Operation DarkSeoul, Dark Seoul, Hidden Cobra, Hastati Group, Andariel, Unit 121, Bureau 121, NewRomanic Cyber Army Team, Bluenoroff, Subgroup: Bluenoroff, Group 77, Labyrinth Chollima, Operation Troy, Operation GhostSecret, Operation AppleJeus, APT38, APT 38, Stardust Chollima, Whois Hacking Team, Zinc, Appleworm, Nickel Academy, APT-C-26, NICKEL GLADSTONE, COVELLITE, ATK3, G0032, ATK117, G0082, Citrine Sleet, DEV-0139, DEV-1222, Diamond Sleet, ZINC, Sapphire Sleet, COPERNICIUM, TA404, Lazarus group, BeagleBoyz, Moonstone Sleet, Black Artemis, HIDDEN COBRA, Guardians of Peace, NICKEL ACADEMY
Description
[Lazarus Group](https://attack.mitre.org/groups/G0032) is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber Groups September 2019) [Lazarus Group](https://attack.mitre.org/groups/G0032) has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by [Lazarus Group](https://attack.mitre.org/groups/G0032) correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.(Citation: Novetta Blockbuster) North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.(Citation: Mandiant DPRK Laz Org Breakdown 2022)(Citation: Mandiant DPRK Groups 2023)(Citation: JPCert Blog Laz Subgroups 2025)
Techniques by tactic
Command and Control
- T1001.003 · Protocol or Service Impersonation
- T1008 · Fallback Channels
- T1071.001 · Web Protocols
- T1090.001 · Internal Proxy
- T1090.002 · External Proxy
- T1102.002 · Bidirectional Communication
- T1104 · Multi-Stage Channels
- T1105 · Ingress Tool Transfer
- T1132.001 · Standard Encoding
- T1571 · Non-Standard Port
- T1573.001 · Symmetric Cryptography
Discovery
- T1010 · Application Window Discovery
- T1012 · Query Registry
- T1016 · System Network Configuration Discovery
- T1033 · System Owner/User Discovery
- T1046 · Network Service Discovery
- T1049 · System Network Connections Discovery
- T1057 · Process Discovery
- T1082 · System Information Discovery
- T1083 · File and Directory Discovery
- T1124 · System Time Discovery
- T1680 · Local Storage Discovery
Stealth
- T1027.007 · Dynamic API Resolution
- T1027.009 · Embedded Payloads
- T1027.013 · Encrypted/Encoded File
- T1036.003 · Rename Legitimate Utilities
- T1036.004 · Masquerade Task or Service
- T1036.005 · Match Legitimate Resource Name or Location
- T1055.001 · Dynamic-link Library Injection
- T1070 · Indicator Removal
- T1070.003 · Clear Command History
- T1070.004 · File Deletion
- T1070.006 · Timestomp
- T1078 · Valid Accounts
- T1134.002 · Create Process with Token
- T1140 · Deobfuscate/Decode Files or Information
- T1202 · Indirect Command Execution
- T1218 · System Binary Proxy Execution
- T1218.005 · Mshta
- T1218.011 · Rundll32
- T1542.003 · Bootkit
- T1564.001 · Hidden Files and Directories
- T1574.001 · DLL
- T1574.013 · KernelCallbackTable
- T1620 · Reflective Code Loading
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Lazarus Group today — this states the absence of a published link, not that Lazarus Group has no infrastructure.
References
- https://threatpost.com/operation-blockbuster-coalition-ties-destructive-attacks-to-lazarus-group/116422/
- https://www.us-cert.gov/ncas/alerts/TA17-164A
- https://www.us-cert.gov/ncas/alerts/TA17-318A
- https://www.us-cert.gov/ncas/alerts/TA17-318B
- https://securelist.com/operation-applejeus/87553/
- https://securelist.com/lazarus-under-the-hood/77908/
- https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity
- https://www.mcafee.com/enterprise/en-us/assets/white-papers/wp-dissecting-operation-troy.pdf
- https://www.bleepingcomputer.com/news/security/north-korean-hackers-are-up-to-no-good-again/
- https://www.cfr.org/interactive/cyber-operations/lazarus-group
- https://www.cfr.org/interactive/cyber-operations/operation-ghostsecret
- https://www.cfr.org/interactive/cyber-operations/compromise-cryptocurrency-exchanges-south-korea
- https://www.bleepingcomputer.com/news/security/lazarus-group-deploys-its-first-mac-malware-in-cryptocurrency-exchange-hack/
- https://content.fireeye.com/apt/rpt-apt38
- https://blog.malwarebytes.com/threat-analysis/2019/03/the-advanced-persistent-threat-files-lazarus-group/
- https://www.theguardian.com/world/2009/jul/08/south-korea-cyber-attack
- https://web.archive.org/web/20131123012339/https://www.symantec.com/connect/blogs/trojankoredos-comes-unwelcomed-surprise
- https://www.nytimes.com/2013/03/21/world/asia/south-korea-computer-network-crashes.html
- https://web.archive.org/web/20130607233212/https://www.symantec.com/connect/blogs/south-korean-financial-companies-targeted-castov
- https://web.archive.org/web/20130701021735/https://www.symantec.com/connect/blogs/four-years-darkseoul-cyberattacks-against-south-korea-continue-anniversary-korean-war
- https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/the-hack-of-sony-pictures-what-you-need-to-know
- https://blog.trendmicro.com/trendlabs-security-intelligence/new-killdisk-variant-hits-financial-organizations-in-latin-america/
- https://www.welivesecurity.com/2018/04/03/lazarus-killdisk-central-american-casino/
- https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/hidden-cobra-targets-turkish-financial-sector-new-bankshot-implant/
- https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/analyzing-operation-ghostsecret-attack-seeks-to-steal-data-worldwide/
- https://www.us-cert.gov/ncas/analysis-reports/AR19-129A
- https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/operation-sharpshooter-targets-global-defense-critical-infrastructure/
- https://securelist.com/cryptocurrency-businesses-still-being-targeted-by-lazarus/90019/
- https://www.theregister.co.uk/2019/04/10/lazarus_group_malware/
- https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Report.pdf
- https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and
- https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/a-look-into-the-lazarus-groups-operations
- https://www.kaspersky.com/about/press-releases/2017_chasing-lazarus-a-hunt-for-the-infamous-hackers-to-prevent-large-bank-robberies
- https://medium.com/threat-intel/lazarus-attacks-wannacry-5fdeddee476c
- https://attack.mitre.org/groups/G0032/
- https://threatpost.com/lazarus-apt-spinoff-linked-to-banking-hacks/124746/
- https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=5b9850b9-0fdd-48a9-b595-9234207ae7df&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments
- https://www.bankinfosecurity.com/vietnamese-bank-blocks-1-million-online-heist-a-9105
- https://www.reuters.com/article/us-cyber-heist-swift-specialreport-idUSKCN0YB0DD
- https://web.archive.org/web/20160527050022/https://www.symantec.com/connect/blogs/swift-attackers-malware-linked-more-financial-attacks
- https://symantec-blogs.broadcom.com/blogs/threat-intelligence/fastcash-lazarus-atm-malware
- https://blog.trendmicro.com/trendlabs-security-intelligence/what-we-can-learn-from-the-bangladesh-central-bank-cyber-heist/
- https://www.symantec.com/connect/blogs/attackers-target-dozens-global-banks-new-malware
- https://baesystemsai.blogspot.com/2017/10/taiwan-heist-lazarus-tools.html
- https://www.bloomberg.com/news/articles/2018-05-29/mexico-foiled-a-110-million-bank-heist-then-kept-it-a-secret
- https://threatpost.com/banco-de-chile-wiper-attack-just-a-cover-for-10m-swift-heist/132796/
- https://www.darkreading.com/attacks-breaches/north-korean-hacking-group-steals-$135-million-from-indian-bank-/d/d-id/1332678
- https://www.zdnet.com/article/north-korean-hackers-infiltrate-chiles-atm-network-after-skype-job-interview/
- https://blogs.jpcert.or.jp/en/2020/08/Lazarus-malware.html
- https://www.secureworks.com/research/threat-profiles/nickel-gladstone
- https://blogs.jpcert.or.jp/en/2020/09/BLINDINGCAN.html
- https://www.welivesecurity.com/2020/11/16/lazarus-supply-chain-attack-south-korea/
- https://dragos.com/adversaries.html
- https://dragos.com/media/2017-Review-Industrial-Control-System-Threats.pdf
- https://www.cfr.org/interactive/cyber-operations/covellite
- https://www.hvs-consulting.de/lazarus-report/
- https://github.com/hvs-consulting/ioc_signatures/tree/main/Lazarus_APT37
- https://blogs.jpcert.or.jp/en/2021/01/Lazarus_tools.html
- https://blogs.jpcert.or.jp/en/2021/01/Lazarus_malware2.html
- https://attack.mitre.org/groups/G0082
- https://attack.mitre.org/groups/G0032
- https://www.microsoft.com/en-us/security/blog/2022/12/06/dev-0139-launches-targeted-attacks-against-the-cryptocurrency-industry/
- https://www.proofpoint.com/us/blog/threat-insight/ta444-apt-startup-aimed-at-your-funds
- https://www.proofpoint.com/us/blog/threat-insight/above-fold-and-your-inbox-tracing-state-aligned-activity-targeting-journalists
- https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Cyber-Sicherheitslage/Analysen-und-Prognosen/Threat-Intelligence/Aktive_APT-Gruppen/aktive-apt-gruppen_node.html
- https://www.securonix.com/blog/securonix-threat-labs-monthly-intelligence-insights-june-2023/
- https://us-cert.cisa.gov/ncas/alerts/aa21-048a
- https://www.microsoft.com/en-us/security/blog/2024/08/30/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/
- https://web.archive.org/web/20210723190317/https://adversary.crowdstrike.com/en-US/adversary/labyrinth-chollima/
- https://cloud.google.com/blog/topics/threat-intelligence/north-korea-cyber-structure-alignment-2023
- https://cloud.google.com/blog/topics/threat-intelligence/mapping-dprk-groups-to-government/
- https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/microsoft-threat-actor-naming?view=o365-worldwide
- https://web.archive.org/web/20160226161828/https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Report.pdf
- https://www.secureworks.com/about/press/media-alert-secureworks-discovers-north-korean-cyber-threat-group-lazarus-spearphishing
- https://blogs.microsoft.com/on-the-issues/2017/12/19/microsoft-facebook-disrupt-zinc-malware-attack-protect-customers-internet-ongoing-cyberthreats/
- https://home.treasury.gov/news/press-releases/sm774
- https://www.us-cert.gov/ncas/analysis-reports/AR19-100A
- https://blogs.jpcert.or.jp/en/2025/03/classifying-lazaruss-subgroup.html
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Lazarus Group into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.