news.mlab.sh
Threat intelligence
Threat actor

Lazarus Group

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
North Korea
Targeted countries
North Korea
TLP
WHITE

(Malwarebytes) Lazarus Group is commonly believed to be run by the North Korean government, motivated primarily by financial gain as a method of circumventing long-standing sanctions against the regime. They first came to substantial media notice in 2013 with a series of coordinated attacks against an assortment of South Korean broadcasters and financial institutions using DarkSeoul, a wiper program that overwrites sections of the victims’ master boot record. In November 2014, a large scale breach of Sony Pictures was attributed to Lazarus. The attack was notable due to its substantial penetration across Sony networks, the extensive amount of data exfiltrated and leaked, as well of use of a wiper in a possible attempt to erase forensic evidence. Attribution on the attacks was largely hazy, but the FBI released a statement tying the Sony breach to the earlier DarkSeoul attack, and officially attributed both incidents to North Korea. Fast forward to May 2017 with the widespread outbreak of WannaCry, a piece of ransomware that used an SMB exploit as an attack vector. Attribution to North Korea rested largely on code reuse between WannaCry and previous North Korean attacks, but this was considered to be thin grounds given the common practice of tool sharing between regional threat groups. Western intelligence agencies released official statements to the public reaffirming the attribution, and on September 6, 2018, the US Department of Justice charged a North Korean national with involvement in both WannaCry and the Sony breach. Lazarus Group has 3 subgroups: 1. Subgroup: Andariel, Silent Chollima 2. Subgroup: BeagleBoyz 3. Subgroup: Bluenoroff, APT 38, Stardust Chollima 4. Subgroup: Operation Contagious Interview The following groups may be associated with the Lazarus Group: Covellite, Reaper, APT 37, Ricochet Chollima, ScarCruft, Wassonite and Moonstone Sleet.

Also known as

AppleJeusApplewormAPT-C-26ATK 3Citrine SleetDEV-0139Diamond SleetG0032Gleaming PiscesGods ApostlesGods DisciplesGroup 77Guardians of PeaceHastati GroupHidden CobraITG03Jade SleetLabyrinth ChollimaLazarus GroupNewRomanic Cyber Army TeamNICKEL ACADEMYSectorA01Slow PiscesTA404TraderTraitorUNC1720UNC2970UNC4034UNC4736UNC4899UNC577Whois Hacking TeamZinc

Vulnerabilities exploited

Tooling and malware

AppleJeusAuditCredBADCALLBankshotBLINDINGCANCryptoisticDaclsDtrackECCENTRICBANDWAGONFALLCHILLHARDRAINHOPLIGHTHotCroissantKEYMARBLEMagicRATProxysvcRATANKBATAINTEDSCRIBEThreatNeedleTYPEFRAMEVolgmerWannaCrynetshRawDiskResponderroute

MITRE ATT&CK techniques

T1005 Data from Local SystemT1560 Archive Collected DataT1008 Fallback ChannelsT1104 Multi-Stage ChannelsT1105 Ingress Tool TransferT1571 Non-Standard PortT1685 Disable or Modify ToolsT1010 Application Window DiscoveryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1033 System Owner/User DiscoveryT1046 Network Service DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1124 System Time DiscoveryT1680 Local Storage DiscoveryT1047 Windows Management InstrumentationT1106 Native APIT1203 Exploitation for Client ExecutionT1041 Exfiltration Over C2 ChannelT1485 Data DestructionT1489 Service StopT1529 System Shutdown/RebootT1657 Financial TheftT1189 Drive-by CompromiseT1566 PhishingT1098 Account ManipulationT1591 Gather Victim Org InformationT1070 Indicator RemovalT1078 Valid AccountsT1140 Deobfuscate/Decode Files or InformationT1202 Indirect Command ExecutionT1218 System Binary Proxy ExecutionT1620 Reflective Code Loading

Coverage 23