Threat intelligence
- Suspected origin
- North Korea
- Targeted countries
- North Korea
- TLP
- WHITE
(Malwarebytes) Lazarus Group is commonly believed to be run by the North Korean government, motivated primarily by financial gain as a method of circumventing long-standing sanctions against the regime. They first came to substantial media notice in 2013 with a series of coordinated attacks against an assortment of South Korean broadcasters and financial institutions using DarkSeoul, a wiper program that overwrites sections of the victims’ master boot record.
In November 2014, a large scale breach of Sony Pictures was attributed to Lazarus. The attack was notable due to its substantial penetration across Sony networks, the extensive amount of data exfiltrated and leaked, as well of use of a wiper in a possible attempt to erase forensic evidence. Attribution on the attacks was largely hazy, but the FBI released a statement tying the Sony breach to the earlier DarkSeoul attack, and officially attributed both incidents to North Korea.
Fast forward to May 2017 with the widespread outbreak of WannaCry, a piece of ransomware that used an SMB exploit as an attack vector. Attribution to North Korea rested largely on code reuse between WannaCry and previous North Korean attacks, but this was considered to be thin grounds given the common practice of tool sharing between regional threat groups. Western intelligence agencies released official statements to the public reaffirming the attribution, and on September 6, 2018, the US Department of Justice charged a North Korean national with involvement in both WannaCry and the Sony breach.
Lazarus Group has 3 subgroups:
1. Subgroup: Andariel, Silent Chollima
2. Subgroup: BeagleBoyz
3. Subgroup: Bluenoroff, APT 38, Stardust Chollima
4. Subgroup: Operation Contagious Interview
The following groups may be associated with the Lazarus Group: Covellite, Reaper, APT 37, Ricochet Chollima, ScarCruft, Wassonite and Moonstone Sleet.
Also known as
AppleJeusApplewormAPT-C-26ATK 3Citrine SleetDEV-0139Diamond SleetG0032Gleaming PiscesGods ApostlesGods DisciplesGroup 77Guardians of PeaceHastati GroupHidden CobraITG03Jade SleetLabyrinth ChollimaLazarus GroupNewRomanic Cyber Army TeamNICKEL ACADEMYSectorA01Slow PiscesTA404TraderTraitorUNC1720UNC2970UNC4034UNC4736UNC4899UNC577Whois Hacking TeamZinc
Vulnerabilities exploited
Tooling and malware
AppleJeusAuditCredBADCALLBankshotBLINDINGCANCryptoisticDaclsDtrackECCENTRICBANDWAGONFALLCHILLHARDRAINHOPLIGHTHotCroissantKEYMARBLEMagicRATProxysvcRATANKBATAINTEDSCRIBEThreatNeedleTYPEFRAMEVolgmerWannaCrynetshRawDiskResponderroute
MITRE ATT&CK techniques
T1005 Data from Local SystemT1560 Archive Collected DataT1008 Fallback ChannelsT1104 Multi-Stage ChannelsT1105 Ingress Tool TransferT1571 Non-Standard PortT1685 Disable or Modify ToolsT1010 Application Window DiscoveryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1033 System Owner/User DiscoveryT1046 Network Service DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1124 System Time DiscoveryT1680 Local Storage DiscoveryT1047 Windows Management InstrumentationT1106 Native APIT1203 Exploitation for Client ExecutionT1041 Exfiltration Over C2 ChannelT1485 Data DestructionT1489 Service StopT1529 System Shutdown/RebootT1657 Financial TheftT1189 Drive-by CompromiseT1566 PhishingT1098 Account ManipulationT1591 Gather Victim Org InformationT1070 Indicator RemovalT1078 Valid AccountsT1140 Deobfuscate/Decode Files or InformationT1202 Indirect Command ExecutionT1218 System Binary Proxy ExecutionT1620 Reflective Code Loading
Coverage 23
vulnerability
Microsoft has patched a critical vulnerability in Entra ID, which has been exploited in the wild. The flaw allows remote code execution, and while Microsoft has addressed it, it highlights the ongoing need for vigilance…

threat-intel
This week saw a surge in exploitation activity and new malware discoveries. A China-nexus APT is leveraging a newly patched VMware vulnerability to deploy a backdoor and ransomware (Babuk-derived). Simultaneously, a zero…

threat-intel
North Korean IT workers are increasingly infiltrating government and businesses by securing jobs through traditional hiring processes. The FBI is currently investigating a case where a North Korean remote worker was hire…

threat-intel
The Lazarus Group, a North Korean threat actor, is exploiting a newly patched zero-day vulnerability in Microsoft Windows' AFD.sys driver to gain SYSTEM access and deploy a backdoor called Troy. They are leveraging a sop…

vulnerability
Microsoft released a massive update with 62 critical and 357 important security vulnerabilities, marking a significant increase in the number of flaws discovered and highlighting the growing role of AI in vulnerability d…

threat-intel
The CISA has ordered federal agencies to patch a critical Windows vulnerability being actively exploited by North Korean hackers as part of Operation ‘Dream Job’. This campaign, led by the Lazarus Group, impersonates rec…

threat-intel
North Korean hackers, operating under the Lazarus Group, are exploiting a recently patched Windows zero-day vulnerability (CVE-2026-68820) to conduct targeted attacks against defense, aerospace, and aviation organization…
vulnerability
Microsoft released a security update containing 398 new vulnerabilities, with one zero-day flaw actively being exploited by Check Point Research's Lazarus group as part of Operation Dream Job. This zero-day (CVE-2026-688…

vulnerability
Microsoft released a substantial update addressing 421 vulnerabilities, including a critical zero-day exploit in a kernel-mode driver (afd.sys). Threat actors, potentially including nation-state actors like those linked…
threat-intel
Security researchers simulated a cryptocurrency startup and hired three individuals they believe were North Korean operatives to test recruitment processes and identify potential risks. The operation involved sophisticat…

ransomware
The Gunra ransomware group, linked to state-sponsored actors, is aggressively targeting critical infrastructure and organizations globally, leveraging vulnerabilities in Fortinet and Schneider Electric appliances to gain…

threat-intel
The FBI and South Korea’s government have issued a cybersecurity advisory warning of the Gunra ransomware gang, which is exploiting vulnerabilities in Fortinet firewalls to target critical infrastructure organizations gl…
