{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "lazarus",
    "slug": "lazarus-group",
    "name": "Lazarus Group",
    "shortName": "Lazarus",
    "country": "North Korea",
    "countryCode": "KP",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2009",
    "prominence": 96,
    "mitreGroupId": "G0032",
    "malpediaSlug": "lazarus_group",
    "tagline": "The only state actor whose primary mission is theft. Stole $1.5 billion from a single exchange in 2025 — the largest heist in history, of any kind.",
    "bio": "Lazarus Group operates under North Korea's Reconnaissance General Bureau and is unique among state actors in that revenue generation is a core, sanctioned mission rather than a sideline.\n\nThe scale is difficult to overstate. UN Panel of Experts reporting has assessed that DPRK cyber operations have generated billions of dollars, with a substantial share directed to the country's weapons programmes. In February 2025 the group stole approximately $1.5 billion in cryptocurrency from the Bybit exchange — the largest theft, by value, ever recorded by any method.\n\nIts history spans the full range of state cyber activity. The 2014 destruction of Sony Pictures Entertainment's network, in retaliation for a film depicting Kim Jong Un's assassination, combined data theft, public leaking, and disk wiping. The 2016 Bangladesh Bank operation abused SWIFT credentials to attempt $951 million in fraudulent transfers, succeeding with $81 million before a spelling error in one instruction — \"fandation\" for \"foundation\" — triggered a manual review. WannaCry in May 2017 spread through EternalBlue to over 200,000 machines in 150 countries, disabling substantial parts of the UK's National Health Service.\n\nIts most refined technique is patient social engineering of individual engineers. Operation Dream Job and its successors approach developers at cryptocurrency and defence firms with fabricated recruitment offers, conduct multi-round interviews, and deliver malware inside a \"coding assessment\" the candidate is asked to run. In the 2023 JumpCloud and 3CX incidents this produced cascading supply-chain compromise — 3CX being the first publicly documented instance of one software supply-chain attack being used to stage another.\n\nThe DPRK also runs a parallel programme placing IT workers in remote roles at Western companies under false identities, generating salary revenue and, in some cases, insider access.",
    "attribution": {
      "sponsor": "North Korea",
      "service": "RGB — Reconnaissance General Bureau",
      "unit": "Lab 110 / 3rd Bureau",
      "unitDetail": "Also reported as Bureau 121; Chosun Expo Joint Venture used as a front",
      "confidence": "confirmed",
      "summary": "Attributed to the Reconnaissance General Bureau by U.S. federal indictment. Park Jin Hyok was charged in September 2018 over the Sony, Bangladesh Bank, and WannaCry operations; a February 2021 superseding indictment added Jon Chang Hyok and Kim Il, covering cryptocurrency theft and the fraudulent Marine Chain token scheme. The indictments identify the defendants as RGB members operating in part through the front company Chosun Expo. The U.S. Treasury has sanctioned Lazarus, Bluenoroff, and Andariel as RGB-controlled entities.",
      "sources": [
        {
          "org": "U.S. Department of Justice",
          "title": "North Korean Regime-Backed Programmer Charged with Conspiracy to Conduct Multiple Cyber Attacks and Intrusions",
          "url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and",
          "date": "2018-09-06"
        },
        {
          "org": "U.S. Department of Justice",
          "title": "Three North Korean Military Hackers Indicted in Wide-Ranging Scheme to Commit Cyberattacks and Financial Crimes",
          "url": "https://www.justice.gov/opa/pr/three-north-korean-military-hackers-indicted-wide-ranging-scheme-commit-cyberattacks-and",
          "date": "2021-02-17"
        },
        {
          "org": "U.S. Department of the Treasury",
          "title": "Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups",
          "url": "https://home.treasury.gov/news/press-releases/sm774",
          "date": "2019-09-13"
        }
      ]
    },
    "motivations": [
      "financial-gain",
      "espionage",
      "sabotage"
    ],
    "targetSectors": [
      "Cryptocurrency",
      "Financial Services",
      "Defense",
      "Aerospace",
      "Technology",
      "Government",
      "Healthcare",
      "Media & Journalism",
      "Energy",
      "Education"
    ],
    "targetCountries": [
      "United States",
      "South Korea",
      "Japan",
      "United Kingdom",
      "India",
      "Bangladesh",
      "Poland",
      "Chile",
      "Vietnam",
      "Germany"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "Lazarus Group",
        "url": "https://attack.mitre.org/groups/G0032/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Diamond Sleet",
        "correlation": "exact",
        "note": "Formerly ZINC"
      },
      {
        "org": "microsoft",
        "name": "ZINC",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Labyrinth Chollima",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "APT38",
        "correlation": "partial",
        "note": "Mandiant separates the financially motivated element as APT38; other vendors treat it as a Lazarus subgroup"
      },
      {
        "org": "mandiant",
        "name": "TEMP.Hermit",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "NICKEL ACADEMY",
        "correlation": "exact"
      },
      {
        "org": "unit42",
        "name": "Slow Pisces",
        "correlation": "partial",
        "note": "Unit 42 cluster for the cryptocurrency-focused subset"
      },
      {
        "org": "kaspersky",
        "name": "Lazarus",
        "correlation": "exact"
      },
      {
        "org": "eset",
        "name": "Lazarus",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "HIDDEN COBRA",
        "correlation": "exact",
        "note": "U.S. government designator used across CISA advisories"
      },
      {
        "org": "symantec",
        "name": "Appleworm",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "TAG-71",
        "correlation": "partial",
        "note": "Provisional designator overlapping DPRK financial operations"
      }
    ],
    "tools": [
      {
        "name": "WannaCry",
        "type": "ransomware",
        "custom": true,
        "description": "Worm-propagating ransomware using EternalBlue; hit 200,000+ machines across 150 countries in May 2017.",
        "malpediaSlug": "win.wannacryptor"
      },
      {
        "name": "AppleJeus",
        "type": "malware",
        "custom": true,
        "description": "Trojanised cryptocurrency trading applications distributed through convincing fake company websites, with macOS and Windows builds.",
        "malpediaSlug": "osx.applejeus"
      },
      {
        "name": "Operation Dream Job lures",
        "type": "utility",
        "custom": true,
        "description": "Fabricated recruitment processes at real defence and crypto firms, delivering malware inside a 'coding assessment'."
      },
      {
        "name": "MagicRAT / QuiteRAT",
        "type": "backdoor",
        "custom": true,
        "description": "Qt-framework backdoors whose large legitimate library footprint frustrates static analysis."
      },
      {
        "name": "BLINDINGCAN",
        "type": "backdoor",
        "custom": true,
        "description": "Backdoor used against defence and aerospace contractors, documented in a CISA advisory.",
        "malpediaSlug": "win.blindingcan"
      },
      {
        "name": "TraderTraitor",
        "type": "malware",
        "custom": true,
        "description": "Malicious npm packages and trojanised trading applications targeting blockchain engineers."
      },
      {
        "name": "FudModule",
        "type": "malware",
        "custom": true,
        "description": "Kernel rootkit that disables EDR from kernel space via a bring-your-own-vulnerable-driver technique."
      },
      {
        "name": "Tornado Cash / mixers",
        "type": "utility",
        "custom": false,
        "description": "Cryptocurrency mixing services used to launder stolen funds; sanctioned by OFAC in August 2022."
      }
    ],
    "techniques": [
      {
        "tCode": "T1566.003",
        "name": "Phishing: Spearphishing via Service",
        "tactic": "Initial Access",
        "note": "LinkedIn and WhatsApp recruitment approaches to individual engineers"
      },
      {
        "tCode": "T1195.002",
        "name": "Supply Chain Compromise: Compromise Software Supply Chain",
        "tactic": "Initial Access",
        "note": "3CX and JumpCloud — the first documented chained supply-chain compromise"
      },
      {
        "tCode": "T1204.002",
        "name": "User Execution: Malicious File",
        "tactic": "Execution",
        "note": "Coding assessments and trading applications run voluntarily by the target"
      },
      {
        "tCode": "T1553.002",
        "name": "Subvert Trust Controls: Code Signing",
        "tactic": "Defense Evasion",
        "note": "Stolen and fraudulently obtained certificates"
      },
      {
        "tCode": "T1068",
        "name": "Exploitation for Privilege Escalation",
        "tactic": "Privilege Escalation",
        "note": "Bring-your-own-vulnerable-driver to reach kernel and disable EDR"
      },
      {
        "tCode": "T1657",
        "name": "Financial Theft",
        "tactic": "Impact",
        "note": "SWIFT fraud, exchange compromise, and direct wallet theft"
      },
      {
        "tCode": "T1486",
        "name": "Data Encrypted for Impact",
        "tactic": "Impact",
        "note": "WannaCry, and Maui ransomware against U.S. healthcare"
      },
      {
        "tCode": "T1485",
        "name": "Data Destruction",
        "tactic": "Impact",
        "note": "Sony Pictures wiper component"
      },
      {
        "tCode": "T1027.009",
        "name": "Obfuscated Files or Information: Embedded Payloads",
        "tactic": "Defense Evasion"
      },
      {
        "tCode": "T1587.002",
        "name": "Develop Capabilities: Code Signing Certificates",
        "tactic": "Resource Development"
      },
      {
        "tCode": "T1583.001",
        "name": "Acquire Infrastructure: Domains",
        "tactic": "Resource Development",
        "note": "Fully fabricated company websites with staff pages and product documentation"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2017-0144",
        "firstExploited": "2017-05-12",
        "usage": "EternalBlue built into WannaCry's propagation engine, producing worm-speed spread across 150 countries within hours and disabling a substantial part of the UK National Health Service.",
        "source": {
          "org": "NCSC-UK",
          "title": "Foreign Office Minister condemns North Korean actor for WannaCry attacks",
          "url": "https://www.ncsc.gov.uk/news/foreign-office-minister-condemns-north-korean-actor-wannacry-attacks",
          "date": "2017-12-19"
        }
      },
      {
        "cveId": "CVE-2018-4878",
        "firstExploited": "2018-01-31",
        "zeroDay": true,
        "usage": "Adobe Flash use-after-free exploited as a zero-day against South Korean targets before Adobe issued a patch.",
        "source": {
          "org": "KrCERT / Cisco Talos",
          "title": "Group 123 goes wild — Flash zero-day exploitation",
          "url": "https://blog.talosintelligence.com/2018/02/group-123-goes-wild.html",
          "date": "2018-02-02"
        }
      },
      {
        "cveId": "CVE-2023-42793",
        "firstExploited": "2023-10-01",
        "usage": "JetBrains TeamCity RCE exploited for access to software build pipelines, enabling supply-chain positioning.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Diamond Sleet supply chain compromise and TeamCity exploitation",
          "url": "https://www.microsoft.com/en-us/security/blog/2023/10/18/multiple-north-korean-threat-actors-exploiting-the-teamcity-cve-2023-42793-vulnerability/",
          "date": "2023-10-18"
        }
      },
      {
        "cveId": "CVE-2021-44228",
        "firstExploited": "2022-02-01",
        "usage": "Log4Shell exploited against internet-facing VMware Horizon servers for initial access to enterprise networks.",
        "source": {
          "org": "Cisco Talos",
          "title": "Lazarus and the tale of three RATs",
          "url": "https://blog.talosintelligence.com/lazarus-three-rats/",
          "date": "2022-09-08"
        }
      },
      {
        "cveId": "CVE-2024-21412",
        "firstExploited": "2024-01-01",
        "zeroDay": true,
        "usage": "Windows SmartScreen bypass exploited as a zero-day to deliver payloads without Mark-of-the-Web warnings.",
        "source": {
          "org": "Trend Micro",
          "title": "CVE-2024-21412: Water Hydra targets traders with Microsoft Defender SmartScreen zero-day",
          "url": "https://www.trendmicro.com/en_us/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html",
          "date": "2024-02-13"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "apt38",
        "type": "suspected-subgroup",
        "confidence": "confirmed",
        "note": "APT38 is the financially motivated element operating under the same RGB structure; vendors differ on whether to treat it as distinct or as a Lazarus subgroup."
      },
      {
        "relatedActorId": "andariel",
        "type": "same-sponsor",
        "confidence": "confirmed",
        "note": "Both RGB; Treasury sanctioned Lazarus, Bluenoroff, and Andariel together in September 2019 as RGB-controlled entities."
      },
      {
        "relatedActorId": "kimsuky",
        "type": "same-sponsor",
        "confidence": "high",
        "note": "Both RGB, with different missions — Kimsuky collects intelligence, Lazarus generates revenue."
      },
      {
        "relatedActorId": "apt37",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both DPRK state actors; APT37 is assessed as MSS-aligned rather than RGB."
      }
    ],
    "reports": [
      {
        "org": "U.S. Department of Justice",
        "title": "Indictment: US v. Park Jin Hyok — Sony, Bangladesh Bank, WannaCry",
        "url": "https://www.justice.gov/opa/press-release/file/1092091/download",
        "date": "2018-09-06"
      },
      {
        "org": "CISA / FBI / Treasury",
        "title": "TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies (AA22-108A)",
        "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a",
        "date": "2022-04-18"
      },
      {
        "org": "Mandiant",
        "title": "3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise",
        "date": "2023-04-20"
      },
      {
        "org": "FBI",
        "title": "FBI Identifies Lazarus Group Cyber Actors as Responsible for Theft of $1.5 Billion from Bybit",
        "url": "https://www.ic3.gov/PSA/2025/PSA250226",
        "date": "2025-02-26"
      },
      {
        "org": "UN Panel of Experts",
        "title": "Report of the Panel of Experts on the DPRK — cyber-enabled revenue generation",
        "url": "https://www.un.org/securitycouncil/sanctions/1718/panel_experts/reports",
        "date": "2024-03-07"
      }
    ],
    "campaigns": [
      {
        "id": "bybit-2025",
        "actorId": "lazarus",
        "name": "Bybit Exchange Theft",
        "date": "2025-02-21",
        "significance": "landmark",
        "targetSectors": [
          "Cryptocurrency",
          "Financial Services"
        ],
        "targetCountries": [
          "United Arab Emirates"
        ],
        "cveIds": [],
        "summary": "Theft of approximately $1.5 billion in cryptocurrency from the Bybit exchange through compromise of a wallet infrastructure provider and manipulation of a multi-signature transaction interface — the largest theft by value ever recorded, by any method.",
        "sources": [
          {
            "org": "FBI",
            "title": "FBI Identifies Lazarus Group Cyber Actors as Responsible for Theft of $1.5 Billion from Bybit",
            "url": "https://www.ic3.gov/PSA/2025/PSA250226",
            "date": "2025-02-26"
          }
        ]
      },
      {
        "id": "3cx-supply-chain",
        "actorId": "lazarus",
        "name": "3CX Cascading Supply Chain Compromise",
        "date": "2023-03-22",
        "significance": "major",
        "targetSectors": [
          "Technology",
          "Telecommunications",
          "Financial Services",
          "Cryptocurrency"
        ],
        "targetCountries": [
          "United States",
          "United Kingdom",
          "Germany",
          "Australia",
          "Italy"
        ],
        "cveIds": [],
        "summary": "Trojanised 3CX desktop application distributed to a customer base of over 600,000 organisations. The intrusion originated from a prior supply-chain compromise of Trading Technologies' X_TRADER software — the first publicly documented case of one software supply-chain attack being used to stage another.",
        "sources": [
          {
            "org": "Mandiant",
            "title": "3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise",
            "url": "https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise",
            "date": "2023-04-20"
          }
        ]
      },
      {
        "id": "wannacry",
        "actorId": "lazarus",
        "name": "WannaCry",
        "date": "2017-05-12",
        "significance": "landmark",
        "targetSectors": [
          "Healthcare",
          "Manufacturing",
          "Telecommunications",
          "Transportation",
          "Government"
        ],
        "targetCountries": [
          "United Kingdom",
          "Russia",
          "India",
          "Ukraine",
          "Spain",
          "China"
        ],
        "cveIds": [
          "CVE-2017-0144"
        ],
        "summary": "Worm-propagating ransomware using EternalBlue, infecting over 200,000 machines across 150 countries in days. The UK's National Health Service was severely disrupted, with roughly 19,000 appointments cancelled. Spread was halted by the registration of a hardcoded kill-switch domain.",
        "sources": [
          {
            "org": "NCSC-UK",
            "title": "Foreign Office Minister condemns North Korean actor for WannaCry attacks",
            "url": "https://www.ncsc.gov.uk/news/foreign-office-minister-condemns-north-korean-actor-wannacry-attacks",
            "date": "2017-12-19"
          }
        ]
      },
      {
        "id": "bangladesh-bank",
        "actorId": "lazarus",
        "name": "Bangladesh Bank SWIFT Heist",
        "date": "2016-02-04",
        "significance": "landmark",
        "targetSectors": [
          "Financial Services"
        ],
        "targetCountries": [
          "Bangladesh",
          "Philippines",
          "Sri Lanka",
          "United States"
        ],
        "cveIds": [],
        "summary": "Abuse of SWIFT credentials to attempt $951 million in fraudulent transfers from Bangladesh Bank's account at the Federal Reserve Bank of New York. $81 million was successfully moved before a misspelling — 'fandation' for 'foundation' — triggered manual review of the remaining instructions.",
        "sources": [
          {
            "org": "U.S. Department of Justice",
            "title": "Indictment: US v. Park Jin Hyok",
            "url": "https://www.justice.gov/opa/press-release/file/1092091/download",
            "date": "2018-09-06"
          }
        ]
      },
      {
        "id": "sony-2014",
        "actorId": "lazarus",
        "name": "Sony Pictures Entertainment",
        "date": "2014-11-24",
        "significance": "landmark",
        "targetSectors": [
          "Media & Journalism",
          "Technology"
        ],
        "targetCountries": [
          "United States"
        ],
        "cveIds": [],
        "summary": "Destruction of Sony Pictures' network alongside theft and public release of unreleased films, employee personal data, and internal email, in retaliation for a film depicting the assassination of Kim Jong Un. The first major destructive attack on a U.S. company attributed to a state.",
        "sources": [
          {
            "org": "FBI",
            "title": "Update on Sony Investigation",
            "url": "https://www.fbi.gov/news/press-releases/update-on-sony-investigation",
            "date": "2014-12-19"
          }
        ]
      }
    ],
    "flag": "🇰🇵",
    "profile": "/apt/lazarus-group/"
  }
}