Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Lazarus Group

Also known as: Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet, Group 77, Hastati Group, Bureau 121, Unit 121, Whois Hacking Team, NewRomanic Cyber Army Team, Appleworm, Operation DarkSeoul, Dark Seoul, Andariel, Bluenoroff, Subgroup: Bluenoroff, Operation Troy, Operation GhostSecret, Operation AppleJeus, APT38, APT 38, Stardust Chollima, APT-C-26, NICKEL GLADSTONE, COVELLITE, ATK3, G0032, ATK117, G0082, Citrine Sleet, DEV-0139, DEV-1222, Sapphire Sleet, COPERNICIUM, TA404, Lazarus group, BeagleBoyz, Moonstone Sleet, Black Artemis, OperationTroy, Guardian of Peace, GOP, WHOis Team, Subgroup: Andariel, Onyx Sleet, PLUTONIUM, ElectricFish, Silent Chollima

Description

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber Groups September 2019) Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.(Citation: Novetta Blockbuster) North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.(Citation: Mandiant DPRK Laz Org Breakdown 2022)(Citation: Mandiant DPRK Groups 2023)(Citation: JPCert Blog Laz Subgroups 2025)

TTP Summary

Troy; Blockbuster; Dark Seoul; Applejeus; Delivery: usually via spear phishing email. Infrastructure: C2 often based on compromised servers,moving to own servers paid by bitcoin to preserve anonymity Persistency: tipically launching ransomware after operation to destroy evidences

Goals & Targeting

Targeted Sectors

Government
Financial services
Technology

Targeted Countries / Regions

US

AI Analysis

· 2 months ago

Executive Summary

Lazarus Group, a North Korean state-sponsored cyber threat group, has been active since at least 2009, conducting financially motivated campaigns, espionage, and destructive attacks. The group is known for its adaptability and use of various techniques, including spear phishing, malware, and ransomware. Lazarus Group has targeted government, financial services, and technology sectors, primarily in the US.

Goals & Targeting

Lazarus Group's strategic objectives and targeting profile are primarily driven by financial gain. The group has targeted government, financial services, and technology sectors, primarily in the US, to achieve its financial goals. Typical victims of Lazarus Group include large financial institutions, government agencies, and technology companies. The group's targeting profile is likely influenced by North Korea's national priorities and the need to generate revenue through cybercrime.

Enhanced Description

Lazarus Group's operations often involve spear phishing emails to deliver malware, which can lead to the deployment of ransomware to destroy evidence. The group's infrastructure typically involves compromised servers, which are later replaced with own servers paid for by bitcoin to preserve anonymity. North Korea's cyber operations have demonstrated a pattern of reorganization and adaptation, with Lazarus Group being an umbrella term for multiple North Korean cyber operators conducting various types of campaigns. Public reporting often uses 'Lazarus Group' to describe the activities of these operators, making it essential to consider the context and specific subgroups when analyzing threat intelligence.

Key Capabilities

  • Spear phishing
  • Malware development and deployment
  • Ransomware attacks
  • Use of compromised servers and bitcoin-paid infrastructure
  • Adaptation and reorganization of units

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Command and Control

ATT&CK Techniques

T1587.001
T1583.004
T1588.001
T1566
T1584.004

Software / Tooling

Wiper
AppleJeus
Flame
Ransomware

Campaigns & Victims

Lazarus Group's campaign patterns typically involve a combination of spear phishing, malware, and ransomware attacks. The group's operational tempo is often characterized by a series of coordinated attacks, followed by a period of relative inactivity. Notable past operations include the attack on Sony Pictures Entertainment, Operation Blockbuster, and Operation AppleJeus. Victim types typically include large financial institutions, government agencies, and technology companies.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Implement robust email security controls to detect and prevent spear phishing attacks
  • Conduct regular security awareness training for employees
  • Use advanced threat detection and protection tools to identify and block malware
  • Develop a comprehensive incident response plan to respond to ransomware attacks

Suggested Tags

APT
ransomware
espionage
finance-sector
state-sponsored

Confidence Assessment

The confidence level in the available data is moderate to high, based on the consistency of reporting from multiple sources, including US-CERT, Treasury, and reputable threat intelligence firms. However, the complexity and adaptability of Lazarus Group's operations, combined with the use of shared infrastructure and tradecraft, introduce some uncertainty and information gaps.

ATT&CK Techniques

Collection
6 techniques
Command & Control
11 techniques
Defense impairment
3 techniques
Discovery
11 techniques
Execution
8 techniques
Impact
6 techniques
Initial Access
4 techniques
Persistence
4 techniques
Resource Development
8 techniques
Stealth
23 techniques

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 5 Domain 12 URL 3

References

  1. CrowdStrike Labyrinth Chollima Feb 2022 — CrowdStrike. (2022, February 1). CrowdStrike Adversary Labyrinth Chollima. Retrieved February 1, 2022.
  2. Mandiant DPRK Groups 2023 — Michael Barnhart, Austin Larsen, Jeff Johnson, Taylor Long, Michelle Cantos, Adrian Hernandez. (2023, October 10). Assessed Cyber Structure and Alignments of North Korea in 2023. Retrieved August 25, 2025.
  3. Mandiant DPRK Laz Org Breakdown 2022 — Michael Barnhart, Michelle Cantos, Jeffery Johnson, Elias fox, Gary Freas, Dan Scott. (2022, March 23). Not So Lazarus: Mapping DPRK Cyber Threat Groups to Government Organizations. Retrieved September 9, 2025.
  4. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  5. Novetta Blockbuster — Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.
  6. Secureworks NICKEL ACADEMY Dec 2017 — Secureworks. (2017, December 15). Media Alert - Secureworks Discovers North Korean Cyber Threat Group, Lazarus, Spearphishing Financial Executives of Cryptocurrency Companies. Retrieved December 27, 2017.
  7. Microsoft ZINC disruption Dec 2017 — Smith, B. (2017, December 19). Microsoft and Facebook disrupt ZINC malware attack to protect customers and the internet from ongoing cyberthreats. Retrieved December 20, 2017.
  8. Treasury North Korean Cyber Groups September 2019 — US Treasury . (2019, September 13). Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups. Retrieved September 29, 2021.
  9. US-CERT HIDDEN COBRA June 2017 — US-CERT. (2017, June 13). Alert (TA17-164A) HIDDEN COBRA – North Korea’s DDoS Botnet Infrastructure. Retrieved July 13, 2017.
  10. US-CERT HOPLIGHT Apr 2019 — US-CERT. (2019, April 10). MAR-10135536-8 – North Korean Trojan: HOPLIGHT. Retrieved April 19, 2019.
  11. JPCert Blog Laz Subgroups 2025 — 佐々木勇人 Hayato Sasaki. (2025, March 25). Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup. Retrieved August 25, 2025.

Intel Summary

93

Techniques

33

Tools

16

Campaigns

100

IOCs

0

Observed Data

14

Tactics

Tags

Ransomware
APT
Phishing
Backdoor / C2
Wiper / Destructive
ransomware
espionage
finance-sector
state-sponsored

Details

MITRE ID
G0032
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
North Korea (KP)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--c93fccb1-e8e8-42cf-ae33-2ad1d183913a
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.