Lazarus Group

⚠️ Critical

Last Updated

Also known as: Andariel, Appleworm, APT 38, APT-C-26, APT38, ATK117, ATK3, BeagleBoyz, Black Artemis, Bluenoroff, Bureau 121, Citrine Sleet, COPERNICIUM, COVELLITE, Dark Seoul, DEV-0139, DEV-1222, Diamond Sleet, G0032, G0082, Group 77, Guardians of Peace, Hastati Group, Hidden Cobra, HIDDEN COBRA, Labyrinth Chollima, Lazarus Group, Lazarus group, Moonstone Sleet, NewRomanic Cyber Army Team, NICKEL ACADEMY, Nickel Academy, NICKEL GLADSTONE, Operation AppleJeus, Operation DarkSeoul, Operation GhostSecret, Operation Troy, Sapphire Sleet, Stardust Chollima, Subgroup: Bluenoroff, TA404, Unit 121, Whois Hacking Team, ZINC, Zinc, Lazarus - APT-C-26, Lazarus, Genie Spider, UNC1069, Alluring Pisces, CageyChameleon, CryptoCore, MASAN

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). US-CERT HIDDEN COBRA June 2017 Treasury North Korean Cyber Groups September 2019 Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. Novetta Blockbuster

North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns. Mandiant DPRK Laz Org Breakdown 2022 Mandiant DPRK Groups 2023 JPCert Blog Laz Subgroups 2025

🌍 Country North Korea
📅 Activity 2009 — 2024
📝 Last Updated
Risk Level Critical
🎯 Incident Type EspionageSabotage
🧭 ATT&CK G0032
Financial Cryptocurrency Entertainment Government Private sector
2009
2024

Introduction

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). US-CERT HIDDEN COBRA June 2017 Treasury North Korean Cyber Groups September 2019 Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. Novetta Blockbuster North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns. Mandiant DPRK Laz Org Breakdown 2022 Mandiant DPRK Groups 2023 JPCert Blog Laz Subgroups 2025

Activities and Tactics

Targeted Sectors: Financial, Cryptocurrency, Entertainment, Government, Private sector

Country of Origin: 🇰🇵 North Korea

Risk Level: Critical

First Seen: 2009

Last Activity: 2024

Incident Type: [“Espionage”, “Sabotage”]

Suspected Victims: South Korea, Bangladesh Bank, Sony Pictures Entertainment, United States, Thailand, France, China, Hong Kong, United Kingdom, Guatemala…

Notable Campaigns

  • Operation Dream Job (C0022): Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star,

Tactics, Techniques, and Procedures (TTPs)

Notable Indicators of Compromise (IOCs)

No atomic indicators are listed in this profile. The APTnotes snapshot indexes 18 public reports that may contain IOCs; see Source Attribution for dataset links.

Malware and Tools

  • Wiper
  • RemoteCMD
  • Remote Utilities
  • RemotePC
  • Whois Wiper:

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: North Korea Additional attribution information pending cataloguing.

References

[1] MITRE ATT&CK MITRE ATT&CK entry [2] US-CERT HIDDEN COBRA June 2017 [3] Treasury North Korean Cyber Groups September 2019 [4] Novetta Blockbuster [5] Mandiant DPRK Laz Org Breakdown 2022 [6] Mandiant DPRK Groups 2023 [7] JPCert Blog Laz Subgroups 2025

Recent News

Latest articles from security news feeds mentioning this actor.