Also known as: Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet, Group 77, Hastati Group, Bureau 121, Unit 121, Whois Hacking Team, NewRomanic Cyber Army Team, Appleworm, Operation DarkSeoul, Dark Seoul, Andariel, Bluenoroff, Subgroup: Bluenoroff, Operation Troy, Operation GhostSecret, Operation AppleJeus, APT38, APT 38, Stardust Chollima, APT-C-26, NICKEL GLADSTONE, COVELLITE, ATK3, G0032, ATK117, G0082, Citrine Sleet, DEV-0139, DEV-1222, Sapphire Sleet, COPERNICIUM, TA404, Lazarus group, BeagleBoyz, Moonstone Sleet, Black Artemis, OperationTroy, Guardian of Peace, GOP, WHOis Team, Subgroup: Andariel, Onyx Sleet, PLUTONIUM, ElectricFish, Silent Chollima
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber Groups September 2019) Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.(Citation: Novetta Blockbuster) North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.(Citation: Mandiant DPRK Laz Org Breakdown 2022)(Citation: Mandiant DPRK Groups 2023)(Citation: JPCert Blog Laz Subgroups 2025)
Troy; Blockbuster; Dark Seoul; Applejeus; Delivery: usually via spear phishing email. Infrastructure: C2 often based on compromised servers,moving to own servers paid by bitcoin to preserve anonymity Persistency: tipically launching ransomware after operation to destroy evidences
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Lazarus Group, a North Korean state-sponsored cyber threat group, has been active since at least 2009, conducting financially motivated campaigns, espionage, and destructive attacks. The group is known for its adaptability and use of various techniques, including spear phishing, malware, and ransomware. Lazarus Group has targeted government, financial services, and technology sectors, primarily in the US.
Goals & Targeting
Lazarus Group's strategic objectives and targeting profile are primarily driven by financial gain. The group has targeted government, financial services, and technology sectors, primarily in the US, to achieve its financial goals. Typical victims of Lazarus Group include large financial institutions, government agencies, and technology companies. The group's targeting profile is likely influenced by North Korea's national priorities and the need to generate revenue through cybercrime.
Enhanced Description
Lazarus Group's operations often involve spear phishing emails to deliver malware, which can lead to the deployment of ransomware to destroy evidence. The group's infrastructure typically involves compromised servers, which are later replaced with own servers paid for by bitcoin to preserve anonymity. North Korea's cyber operations have demonstrated a pattern of reorganization and adaptation, with Lazarus Group being an umbrella term for multiple North Korean cyber operators conducting various types of campaigns. Public reporting often uses 'Lazarus Group' to describe the activities of these operators, making it essential to consider the context and specific subgroups when analyzing threat intelligence.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Lazarus Group's campaign patterns typically involve a combination of spear phishing, malware, and ransomware attacks. The group's operational tempo is often characterized by a series of coordinated attacks, followed by a period of relative inactivity. Notable past operations include the attack on Sony Pictures Entertainment, Operation Blockbuster, and Operation AppleJeus. Victim types typically include large financial institutions, government agencies, and technology companies.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is moderate to high, based on the consistency of reporting from multiple sources, including US-CERT, Treasury, and reputable threat intelligence firms. However, the complexity and adaptability of Lazarus Group's operations, combined with the use of shared infrastructure and tradecraft, introduce some uncertainty and information gaps.
Troy
Blockbuster
Dark Seoul
Applejeus
Campaign Rifle
DesertWolf
Vanxatm
Mayday
INITROY
XEDA
Sony
FASTCash
Far Eastern International Bank
CrowdStrike Falcon Platform Detects and Prevents Active Intrusion Campaign Targeting 3CXDesktopApp Customers
Imported from MISP event #403 (2d2af096-edea-4dde-8be3-0224205b1074).
Mar 29, 2023
TLP:CLEARNo observed data linked yet.
93
Techniques
33
Tools
16
Campaigns
100
IOCs
0
Observed Data
14
Tactics