Lazarus Group

APT / StateG0032 ↗
Origin🇰🇵 Coreia do Norte
Techniques (MITRE ATT&CK)93
SourceMITRE ATT&CK
State sponsor: Korea (Democratic People's Republic of)Attribution confidence: 50%Target categories: Government, Private sector
Targeted regions: South Korea · Bangladesh Bank · Sony Pictures Entertainment · United States · Thailand · France · China · Hong Kong · United Kingdom · Guatemala +9
Also known as:APT 38APT-C-26APT38ATK117ATK3AndarielApplewormBeagleBoyzBlack ArtemisBluenoroffBureau 121COPERNICIUMCOVELLITECitrine SleetDEV-0139DEV-1222Dark SeoulDiamond SleetG0032G0082Group 77Guardians of PeaceHIDDEN COBRAHastati GroupHidden CobraLabyrinth ChollimaMoonstone SleetNICKEL ACADEMYNICKEL GLADSTONENewRomanic Cyber Army TeamNickel AcademyOperation AppleJeusOperation DarkSeoulOperation GhostSecretOperation TroySapphire SleetStardust ChollimaSubgroup: BluenoroffTA404Unit 121Whois Hacking TeamZINCZinc

About the group

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity81
Impact: High
T1189T1047T1098T1110.003T1005T1041ENTRYInitial accessDrive-byCompromiseEXECExecutionWindows ManagementInstrumentationPERSPersistenceAccountManipulationCREDCredential accessPassword SprayingCOLLCollectionData from LocalSystemEXFILExfiltrationExfiltration OverC2 ChannelIMPACTImpactData Destruction

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 93

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 1

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 24

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

sha256_hashb9fcda5008f194cb1d90a7fc1c30ac6240b7ca3fe1dff8c6e7c42c802ba25abdWannaCrymalwarebazaar
sha256_hash79af101b4ef565a38c39f1d11632eedc12624d6d667bf4d3c3f185d12634253eWannaCrymalwarebazaar
sha256_hash6e60aa64951a1561651afe3cf5e03f09d21f2a6ea487a83d60e92fe24456f99bWannaCrymalwarebazaar
sha256_hash6f552e6a9d66594e5e921f715b20ad2c8a5e4ef76277a3eda3e7f36bb99d457dWannaCrymalwarebazaar
sha256_hash3044416f2a33213a25eddda36cf89533d6edf2fed6ea018ee858238099e545deWannaCrymalwarebazaar
sha256_hash8d9a05abe56fdabcd4a3887bb97c37958f9faeb7a66ef751d7a1f0750b97701dWannaCrymalwarebazaar
sha256_hash477aac8eea0636d6b9a853860a312c2c4b8e501c1723894f83f89729c85aa7c7WannaCrymalwarebazaar
sha256_hash6f0f3928fa60d3d51e7fa1cedc94df4ec0b41d7ab5b9c7488715020f6b294455WannaCrymalwarebazaar
sha256_hash99675dee76e7e6ef051bca3da95870d518b53c757d7cdbed045b1137911884b5WannaCrymalwarebazaar
sha256_hashf2257d01dde12339f8bc370eabc74fa487e116b47f61f2094472885b9e4cb631WannaCrymalwarebazaar
sha256_hashed597d3121d614edf3aa79636783ce962732c579f2786c83c5585c43b6847a90WannaCrymalwarebazaar
sha256_hash1e78e60de13290234f642709674835e7b400102d7d22367266fd38329782e58eWannaCrymalwarebazaar
sha256_hash960a43b385f4370b19590ea7c9250acabb0ecb0df4fb8fb28d970bde643dbbd6WannaCrymalwarebazaar
sha256_hash05be5a8131993a5034bc4a57963f0c8860aeb3188dd906ed78d95439d15d813eWannaCrymalwarebazaar
sha256_hash2521192853e4857386d89f555851adfdebde3a939199f939f93068058718e72eWannaCrymalwarebazaar
sha256_hash9767724a6dd381d9401bcd0ea8c082d3b009c59ab949d6e25970f1de848354afWannaCrymalwarebazaar
sha256_hash32c9bf96fb8c0d6ad0d3a3d2707a8a9ae0b95ccefaa26ad0e33b518d9fd0a608WannaCrymalwarebazaar
sha256_hash545bf734fc18a564c334aaf0894295c1e7d123bb4ff274f3ed66f2a16f3bbbabWannaCrymalwarebazaar
sha256_hash71fcbb434b354f3d49979deb66e458086f266f36c6a161e46cd924445bd22c65WannaCrymalwarebazaar
sha256_hash2c2883d25e71c2859b16ac28757e3754f33767931aa98d5a9e705c374818e8f5WannaCrymalwarebazaar
sha256_hash1ab810f65b846b0d1aef311bda3d0e96dcc806dd7bdfc7eb414a68d53786a6adWannaCrymalwarebazaar
sha256_hashe4846ec6171f65e96c2909ad93359451551e3ac95aa89ab349d5ab773cbaa0d6WannaCrymalwarebazaar
sha256_hashbecb96feeca38c60ffe947656e5a7eaadca38be472531ef69efb1e5fe3c02205WannaCrymalwarebazaar
sha256_hash9b90e3a119436b64ead0edfde7a8be2221fce6073f369c4065803320f9bfd655WannaCrymalwarebazaar

Lazarus Group uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →