← Threat Actors / North Korea / Lazarus Group
DOSSIER // LAZARUS-GROUP

Lazarus Group

▲ High Threat North Korea
Primary Aliases: APT38 Citrine Sleet DEV-0139 DEV-0954
Sponsor / State Affiliation Korea (Democratic People's Republic of)
Primary Motivation Espionage, Sabotage
Active Timeline Unknown – Present
Confidence Rating 70% (Grounded)

Since 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltration of data while others have been disruptive in nature. Commercial reporting has referred to this activity as Lazarus Group and Guardians of Peace. Tools and capabilities used by HIDDEN COBRA actors include DDoS botnets, keyloggers, remote access tools (RATs), and wiper malware. Variants of malware and tools used by HIDDEN COBRA actors include Destover, Duuzer, and Hangman.

🎯 Target Sectors & Focus

Financial institutions Cryptocurrency Defense Media Healthcare

🛡️ MITRE ATT&CK® Attack Lifecycle (93 TTPs)

📥 Download Navigator JSON
Exfiltration & Impact 1
Operational Techniques 53
T1000 Protocol or Service Impersonation
T1000 Server
T1000 Mshta
T1000 Malware
T1000 SSH
T1000 Hidden Files and Directories
T1000 Gather Victim Org Information
T1000 Native API
T1000 Embedded Payloads
T1000 External Proxy
T1000 Encrypted/Encoded File
T1000 Multi-Stage Channels
T1000 Data from Local System
T1000 Service Stop
T1000 Digital Certificates
T1000 Symmetric Cryptography
T1000 Reflective Code Loading
T1000 Bidirectional Communication
T1000 Archive Collected Data
T1000 Rename Legitimate Utilities
T1000 Windows Management Instrumentation
T1000 Disable or Modify Tools
T1000 Email Addresses
T1000 Disk Content Wipe
T1000 Internal Defacement
T1000 Tool
T1000 Shortcut Modification
T1000 Visual Basic
T1000 Rundll32
T1000 Web Services
T1000 Non-Standard Port
T1000 Standard Encoding
T1000 Malicious File
T1000 Archive via Library
T1000 Dynamic API Resolution
T1000 File Deletion
T1000 Internal Proxy
T1000 Fallback Channels
T1000 Deobfuscate/Decode Files or Information
T1000 Disk Structure Wipe
T1000 Domains
T1000 Match Legitimate Resource Name or Location
T1000 KernelCallbackTable
T1000 Dynamic-link Library Injection
T1000 Social Media Accounts
T1000 System Shutdown/Reboot
T1000 Masquerade Task or Service
T1000 Clear Command History
T1000 DLL
T1000 Windows Host Firewall
T1000 Windows Service
T1000 Email Accounts
T1000 Archive via Custom Method
Copied to clipboard

LINK COPIED TO CLIPBOARD