Skip to content
North KoreaState-SponsoredActiveMITRE G0032Malpedia ↗

Lazarus Group

The only state actor whose primary mission is theft. Stole $1.5 billion from a single exchange in 2025 — the largest heist in history, of any kind.

ATTRIBUTED TONorth Korea › RGB — Reconnaissance General Bureau › Lab 110 / 3rd Bureau

Open MITRE Navigator layer ↗Download profile JSON
Active
2009–present
Motivation
Financial Gain, Espionage, Sabotage / Destruction
Aliases
13
Exploited CVEs
5
ATT&CK techniques
11
Cited sources
13

Overview

Lazarus Group operates under North Korea's Reconnaissance General Bureau and is unique among state actors in that revenue generation is a core, sanctioned mission rather than a sideline.

The scale is difficult to overstate. UN Panel of Experts reporting has assessed that DPRK cyber operations have generated billions of dollars, with a substantial share directed to the country's weapons programmes. In February 2025 the group stole approximately $1.5 billion in cryptocurrency from the Bybit exchange — the largest theft, by value, ever recorded by any method.

Its history spans the full range of state cyber activity. The 2014 destruction of Sony Pictures Entertainment's network, in retaliation for a film depicting Kim Jong Un's assassination, combined data theft, public leaking, and disk wiping. The 2016 Bangladesh Bank operation abused SWIFT credentials to attempt $951 million in fraudulent transfers, succeeding with $81 million before a spelling error in one instruction — "fandation" for "foundation" — triggered a manual review. WannaCry in May 2017 spread through EternalBlue to over 200,000 machines in 150 countries, disabling substantial parts of the UK's National Health Service.

Its most refined technique is patient social engineering of individual engineers. Operation Dream Job and its successors approach developers at cryptocurrency and defence firms with fabricated recruitment offers, conduct multi-round interviews, and deliver malware inside a "coding assessment" the candidate is asked to run. In the 2023 JumpCloud and 3CX incidents this produced cascading supply-chain compromise — 3CX being the first publicly documented instance of one software supply-chain attack being used to stage another.

The DPRK also runs a parallel programme placing IT workers in remote roles at Western companies under false identities, generating salary revenue and, in some cases, insider access.

Attribution

Down to the named unit where public evidence supports it.

North KoreaRGB — Reconnaissance General BureauLab 110 / 3rd BureauConfirmed

Also reported as Bureau 121; Chosun Expo Joint Venture used as a front

Attributed to the Reconnaissance General Bureau by U.S. federal indictment. Park Jin Hyok was charged in September 2018 over the Sony, Bangladesh Bank, and WannaCry operations; a February 2021 superseding indictment added Jon Chang Hyok and Kim Il, covering cryptocurrency theft and the fraudulent Marine Chain token scheme. The indictments identify the defendants as RGB members operating in part through the front company Chosun Expo. The U.S. Treasury has sanctioned Lazarus, Bluenoroff, and Andariel as RGB-controlled entities.

Attributing sources

Cross-vendor naming crosswalk

13 designators across 11 organisations.

3 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • Lazarus Group

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Diamond SleetFormerly ZINC
  • ZINCRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Labyrinth Chollima

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT38partialMandiant separates the financially motivated element as APT38; other vendors treat it as a Lazarus subgroup
  • TEMP.Hermit

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • NICKEL ACADEMY

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Slow PiscespartialUnit 42 cluster for the cryptocurrency-focused subset

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Recorded Future Insikt Group

index ↗
  • TAG-71partialProvisional designator overlapping DPRK financial operations

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

ESET Research

index ↗
  • Lazarus

Descriptive names, frequently derived from the group's flagship malware family.

Kaspersky GReAT

index ↗
  • Lazarus

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Symantec (Broadcom)

index ↗
  • Appleworm

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • HIDDEN COBRAU.S. government designator used across CISA advisories

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesSouth KoreaJapanUnited KingdomIndiaBangladeshPolandChileVietnamGermany

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

WannaCryransomware

Worm-propagating ransomware using EternalBlue; hit 200,000+ machines across 150 countries in May 2017.

Malpedia ↗
AppleJeusmalware

Trojanised cryptocurrency trading applications distributed through convincing fake company websites, with macOS and Windows builds.

Malpedia ↗
Operation Dream Job luresutility

Fabricated recruitment processes at real defence and crypto firms, delivering malware inside a 'coding assessment'.

MagicRAT / QuiteRATbackdoor

Qt-framework backdoors whose large legitimate library footprint frustrates static analysis.

BLINDINGCANbackdoor

Backdoor used against defence and aerospace contractors, documented in a CISA advisory.

Malpedia ↗
TraderTraitormalware

Malicious npm packages and trojanised trading applications targeting blockchain engineers.

FudModulemalware

Kernel rootkit that disables EDR from kernel space via a bring-your-own-vulnerable-driver technique.

Shared, commodity & living-off-the-land

Tornado Cash / mixersutility

Cryptocurrency mixing services used to launder stolen funds; sanctioned by OFAC in August 2022.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Lazarus Group
CVE-2024-214120-dayKEVransomware8.11 Jan 2024Windows SmartScreen bypass exploited as a zero-day to deliver payloads without Mark-of-the-Web warnings.SRCTrend Micro
CVE-2023-42793KEVransomware9.81 Oct 2023JetBrains TeamCity RCE exploited for access to software build pipelines, enabling supply-chain positioning.SRCMicrosoft Threat Intelligence
CVE-2021-44228KEVransomware10.01 Feb 2022Log4Shell exploited against internet-facing VMware Horizon servers for initial access to enterprise networks.SRCCisco Talos
CVE-2018-48780-dayKEVransomware9.831 Jan 2018Adobe Flash use-after-free exploited as a zero-day against South Korean targets before Adobe issued a patch.SRCKrCERT / Cisco Talos
CVE-2017-0144KEVransomware8.112 May 2017EternalBlue built into WannaCry's propagation engine, producing worm-speed spread across 150 countries within hours and disabling a substantial part of the UK National Health Service.SRCNCSC-UK

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

6 stages · 11 techniques
  1. 03

    Execution

    1 technique

    The target executes it themselves — a take-home exercise, a trading application, an npm dependency. No exploit is required when the victim has been persuaded the file is their job.

  2. 04

    Privilege Escalation

    1 technique

    Brings a vulnerable signed driver and uses it to reach kernel space, from which FudModule disables the endpoint agent that would otherwise be watching.

  3. 06

    Impact

    3 techniques

    Revenue, at state scale. SWIFT transaction manipulation with the printed confirmations suppressed, ATM switch servers approving fraudulent withdrawals, exchange signing interfaces altered so authorised approvers unknowingly sign the theft — $1.5 billion from Bybit in a single operation. Where destruction serves instead, WannaCry and the Sony wiper.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
11 techniques across 6 tactics · 9 with actor-specific notes

Resource Development

2

Initial Access

2

Execution

1

Privilege Escalation

1

Impact

3

Campaign timeline

  1. landmark

    Bybit Exchange Theft

    Theft of approximately $1.5 billion in cryptocurrency from the Bybit exchange through compromise of a wallet infrastructure provider and manipulation of a multi-signature transaction interface — the largest theft by value ever recorded, by any method.

    CryptocurrencyFinancial Services
  2. 3CX Cascading Supply Chain Compromise

    Trojanised 3CX desktop application distributed to a customer base of over 600,000 organisations. The intrusion originated from a prior supply-chain compromise of Trading Technologies' X_TRADER software — the first publicly documented case of one software supply-chain attack being used to stage another.

    TechnologyTelecommunicationsFinancial ServicesCryptocurrency
  3. landmark

    WannaCry

    Worm-propagating ransomware using EternalBlue, infecting over 200,000 machines across 150 countries in days. The UK's National Health Service was severely disrupted, with roughly 19,000 appointments cancelled. Spread was halted by the registration of a hardcoded kill-switch domain.

    CVE-2017-0144HealthcareManufacturingTelecommunicationsTransportation
  4. landmark

    Bangladesh Bank SWIFT Heist

    Abuse of SWIFT credentials to attempt $951 million in fraudulent transfers from Bangladesh Bank's account at the Federal Reserve Bank of New York. $81 million was successfully moved before a misspelling — 'fandation' for 'foundation' — triggered manual review of the remaining instructions.

    Financial Services
  5. landmark

    Sony Pictures Entertainment

    Destruction of Sony Pictures' network alongside theft and public release of unreleased films, employee personal data, and internal email, in retaliation for a film depicting the assassination of Kim Jong Un. The first major destructive attack on a U.S. company attributed to a state.

    Media & JournalismTechnology

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.