Lazarus Group (Comprehensive Profile) — Threat Intelligence Wiki
    Threat Intelligence Wiki Article  |  Talk     Read  |  View source  |  View history

    Lazarus Group

    From Threat Intelligence Wiki, the definitive threat-actor encyclopedia
    Lazarus Group
    🧪
    Flagship Symbol: DPRK State Actor
    Also known asHidden Cobra · Guardians of Peace · ZINC · Labyrinth Chollima · APT38 · Diamond Sleet
    Formationc. 2009 (Unit 121)
    Alleged ParentReconnaissance General Bureau (RGB)
    Operational AimRevenue generation, Espionage, Deterrence
    Primary TargetsFinance, Crypto, Defense, Aerospace
    AttributionHigh Confidence (US, UK, EU, SK)
    Status● Highly Active

    Lazarus Group is a sophisticated, multi-faceted advanced persistent threat (APT) group originating from the Democratic People’s Republic of Korea (North Korea). Attributed to the Reconnaissance General Bureau (RGB), the group is globally unique for its “Hybrid” mission model: combining traditional state-sponsored espionage with large-scale, financially motivated cybercrime.[1]

    Since its inception around 2009, Lazarus has conducted a vast array of cyber operations. These campaigns are unique because they span the entire spectrum of cyber activity: from low-level DDoS attacks used for distraction to sophisticated SWIFT network manipulation and decentralized finance (DeFi) exploits. As of 2026, the group is estimated to have successfully stolen over $3 billion in liquid assets to support the DPRK’s weapons programs and state economy.[2]

    Vendor Naming Conventions:
    Hidden Cobra (FBI/CISA) · ZINC / Diamond Sleet / Jade Sleet (Microsoft) · Labyrinth Chollima / Stardust Chollima (CrowdStrike) · APT38 (Mandiant/Google) · BeagleBoyz (US Cyber Command)

    1 Identity & Organizational Structure [edit]

    Lazarus is not a single entity but a massive umbrella organization containing several highly specialized sub-units, each with its own targets and malware families:

    • BlueNoroff (APT38 / Stardust Chollima): The “Financial Specialists.” Tasked with attacking central banks, the SWIFT system, and cryptocurrency exchanges. They are responsible for the Bangladesh Bank heist and the majority of high-value crypto-thefts.
    • Andariel (Unit 180 / Silent Chollima): The “Espionage & Support” wing. Primarily targets South Korean government, military, and defense firms. They often use ransomware against private companies to generate smaller-scale operational funding.
    • Unit 121: The primary bureau within the RGB that oversees these operations, believed to be staffed by elite graduates of the Mirim College (University of Automation).
    • Kimsuky: While often tracked separately, security researchers note significant code sharing and infrastructure overlap with Lazarus, suggesting they operate under the same RGB umbrella.

    2 Technical Tradecraft & TTPs [edit]

    Lazarus tradecraft is characterized by extreme patience (staying in a network for months before moving funds) and the use of “Living off the Land” (LotL) techniques to evade EDR systems.

    Job Lure Phishing (Operation Dream Job)

    Their most successful initial access vector involves creating high-fidelity LinkedIn or Telegram personas of recruiters from firms like Coinbase, Disney, or Boeing. They engage the target for days before sending a “Job Description” PDF or a “Coding Test” ZIP file that contains a multi-stage downloader.[3]

    Supply Chain Compromise

    Lazarus was the first DPRK actor to master the software supply chain attack. By compromising the developers of a widely-used application (like 3CX or JumpCloud), they gain a foothold into thousands of downstream customer networks simultaneously.

    3 Comprehensive Campaign Archive [edit]

    This section provides a complete record of publicly documented attack campaigns, categorized by their operational evolution.

    Year Campaign Name Target / Description Impact
    2009 Operation Troy DDoS attacks on US/South Korean govt sites. Used to probe defensive responses. System downtime
    2013 DarkSeoul Massive wiper attack against South Korean banks and broadcasters (KBS/MBC). Infrastructure destroyed
    2014 Sony Pictures Hack Retaliation for the film The Interview. Exfiltrated emails and used wipers. $15M+ recovery costs
    2016 Bangladesh Bank Heist SWIFT network manipulation to issue fraudulent transfer instructions. $81M stolen
    2017 WannaCry 2.0 Global ransomware outbreak using EternalBlue exploit. 200k+ PCs affected
    2018 AppleJeus Trojanized crypto-trading apps for macOS and Windows. Ongoing wallet theft
    2022 Ronin Bridge Hack Exploited Axie Infinity’s sidechain via a fake job interview. $620M stolen
    2023 3CX Supply Chain Compromise of the 3CX desktop app installer to distribute malware. 600k+ companies at risk
    2024-25 Conti/Crypto Lures Ongoing targeting of blockchain devs via fake GitHub repositories and tests. Institutional theft

    4 Malware Ecosystem [edit]

    The group maintains a vast, proprietary codebase that is frequently updated to bypass signature-based detection:

    FamilyPurposeCapabilities
    ManuscryptRAT / BackdoorFlagship tool for persistence, keylogging, and file exfiltration.
    MataFrameworkModular architecture targeting Windows, Linux, and macOS simultaneously.
    NukeSpedRemote AdminCustom tool used heavily in “Operation Dream Job” and crypto-theft.
    DtrackSpywareSpecialized in harvesting data from financial kiosks and ATM controllers.
    DestoverWiperThe primary tool for the Sony and DarkSeoul destructive operations.

    5 Laundering & Evasion Tactics [edit]

    To convert stolen digital assets into usable fiat currency, Lazarus has developed the most advanced laundering pipelines in the world:

    “The group’s laundering cycle has evolved from simple ‘Tumblers’ to complex automated ‘Chain-Hopping’ protocols that defy traditional blockchain forensics.”
    • Mixer Utilization: Heavy reliance on Tornado Cash, Sinbad, and Blender.io to break the link between stolen funds and destination wallets.
    • Chain Hopping: Rapidly swapping BTC to ETH, SOL, or USDC through decentralized exchanges (DEXs) to obscure the audit trail.
    • Peeling Chains: Breaking large amounts of stolen funds into thousands of tiny transactions to bypass exchange limits.
    • OTC Brokers: Utilizing over-the-counter brokers in regions with minimal AML/KYC regulations to exit into cash.

    6 Detection & Mitigation [edit]

    Due to Lazarus’s focus on social engineering and legitimate credentials, traditional antivirus is often insufficient.

    • FIDO2 MFA: Enforce phishing-resistant hardware keys. Lazarus has successfully bypassed SMS and TOTP codes in the past.
    • Zero-Trust Browsing: Isolate web browsing and file downloads for employees in defense and crypto sectors.
    • Outbound Traffic Analysis: Monitor for connections to known Lazarus “Stage 1” C2 patterns (often utilizing legitimate but compromised WordPress sites).
    • SWIFT Security: Implement the CSP (Customer Security Programme) controls for any institution handling international transfers.

    References [edit]

    1. U.S. Department of Justice: Indictment of Lazarus Group officers (2018, 2021).
    2. Chainalysis: “North Korean Hackers and the $3.8 Billion Crypto Theft Record.”
    3. Microsoft Threat Intelligence: “Diamond Sleet targets the cryptocurrency industry.”
    4. Kaspersky Lab: “The AppleJeus Evolution: A Comprehensive Breakdown.”
    5. CISA / FBI Joint Advisory on Hidden Cobra (Lazarus Group) TTPs.
    6. Mandiant (Google Cloud): “APT38: Details on the Financial Arm of North Korea.”
    Categories: Advanced Persistent Threats · North Korean State Hacking · RGB · SWIFT Fraud · Cryptocurrency Theft · Supply Chain Attacks · Ransomware Operators
    This page was last synced August 2026. Content is summarized from cross-vendor public threat-intelligence reporting and declassified government advisories.