Lazarus Group

MITRE ATT&CK: G0032 View on attack.mitre.org

Aliases: Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet, Operation DarkSeoul, Dark Seoul, Hidden Cobra, Hastati Group, Andariel, Unit 121, Bureau 121, NewRomanic Cyber Army Team, Bluenoroff, Subgroup: Bluenoroff, Group 77, Operation Troy, Operation GhostSecret, Operation AppleJeus, APT38, APT 38, Stardust Chollima, Whois Hacking Team, Zinc, Appleworm, Nickel Academy, APT-C-26, NICKEL GLADSTONE, COVELLITE, ATK3, ATK117, Citrine Sleet, DEV-0139, DEV-1222, Sapphire Sleet, COPERNICIUM, TA404, Lazarus group, BeagleBoyz, Moonstone Sleet, Black Artemis, Lazarus Group, Storm-0139, Storm-1222, LABYRINTH CHOLLIMA, Lazarus, Genie Spider, BlueNoroff, UNC1069, STARDUST CHOLLIMA, Alluring Pisces, CageyChameleon, CryptoCore

First seen
2009-01-01 00:00:00
Origin
KP
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage, Sabotage
Related IoCs
182 (166 malicious)
Last IoC activity
2026-09-02 00:35:34
Profile updated
2026-07-07 12:34:03

Targeted industries: defense-and-aerospace financial-services government-and-public-sector media-and-entertainment technology-and-telecommunications

Targeted regions: country_code:us country_code:kr country_code:jp country_code:in country_code:vn

Context

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.

Recent IoC activity

166 malicious indicators in Maltiverse are attributed to Lazarus Group (G0032). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname zacharryblogs.com 2026-09-03 4
hostname officeaddons.com 2026-09-03 4
hostname msstorageboxes.com 2026-09-03 4
hostname visualstudiofactory.com 2026-09-03 4
hostname pbxcloudeservices.com 2026-09-03 3
hostname azureonlinestorage.com 2026-09-03 3
hostname ns.thetiscloud1.it 2026-09-03 1
hostname sbmsa.wiki 2026-09-02 4
hostname msstorageazure.com 2026-09-02 4
hostname ns2.x-peditenetworks.com 2026-09-02 1
hostname glcloudservice.com 2026-09-02 4
hostname lightingmart.co.kr 2026-09-02 1
hostname azuredeploystore.com 2026-09-02 3
hostname ns3.x-peditenetworks.com 2026-09-02 1
hostname msedgepackageinfo.com 2026-09-02 3
hostname www.cwnet.it 2026-09-02 1
hostname deck.31ventures.info 2026-09-02 1
hostname www.ne-ba.org 2026-09-02 2
hostname studyholic.co.kr 2026-09-02 1
hostname ns1.x-peditenetworks.com 2026-09-02 1

Detection coverage

  • 32 YARA rules
  • 968 Sigma rules

Malware & tools used

  • Windows Command Shell (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Indirect Command Execution (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • Protocol or Service Impersonation (attack-pattern)
  • Server (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Mshta (attack-pattern)
  • Application Window Discovery (attack-pattern)
  • Malware (attack-pattern)
  • Create Process with Token (attack-pattern)
  • SSH (attack-pattern)
  • Account Manipulation (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Data Destruction (attack-pattern)
  • Gather Victim Org Information (attack-pattern)
  • Native API (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • Query Registry (attack-pattern)
  • External Proxy (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Multi-Stage Channels (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Data from Local System (attack-pattern)

Related threat objects

Reports & references

  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • dragos.com — 2017 Review Industrial Control System Threats (report)
  • dragos.com — Adversaries (report)
  • threatpost.com — 116422 (report)
  • us-cert.gov — Ta17 164A (report)
  • us-cert.gov — Ta17 318A (report)
  • us-cert.gov — Ta17 318B (report)
  • Kaspersky — 87553 (report)
  • Kaspersky — 77908 (report)
  • us-cert.gov — Hidden Cobra North Korean Malicious Cyber Activity (report)
  • McAfee — Wp Dissecting Operation Troy (report)
  • bleepingcomputer.com — North Korean Hackers Are Up To No Good Again (report)
  • cfr.org — Lazarus Group (report)
  • cfr.org — Operation Ghostsecret (report)
  • cfr.org — Compromise Cryptocurrency Exchanges South Korea (report)
  • bleepingcomputer.com — Lazarus Group Deploys Its First Mac Malware In Cryptocurrency Exchange Hack (report)
  • Mandiant — Rpt Apt38 (report)
  • blog.malwarebytes.com — The Advanced Persistent Threat Files Lazarus Group (report)
  • theguardian.com — South Korea Cyber Attack (report)
  • web.archive.org — Trojankoredos Comes Unwelcomed Surprise (report)
  • nytimes.com — South Korea Computer Network Crashes (report)
  • web.archive.org — South Korean Financial Companies Targeted Castov (report)
  • web.archive.org — Four Years Darkseoul Cyberattacks Against South Korea Continue Anniversary Korean War (report)
  • Trend Micro — The Hack Of Sony Pictures What You Need To Know (report)
  • Trend Micro — New Killdisk Variant Hits Financial Organizations In Latin America (report)

Attributed from

  • 2025 Bluenoroff Cryptocurrency Foundation Targeting (campaign)
  • Citrine Sleet Chromium Zero-Day Exploit Activity (CVE-2024-7971) (campaign)
  • Citrine Sleet Cryptocurrency Industry Attack (campaign)
  • Contagious Interview (campaign)
  • Operation Dream Job (campaign)
  • Operation In(ter)ception (campaign)
  • Operation Sharpshooter (campaign)
  • TA455 Iranian Dream Job Campaign (campaign)
  • VMConnect Lazarus Group Campaign (campaign)

External references