🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
LAZARUS GROUP

/actor/lazarus-group/  ·  0 intel reports

Year Established
2009
Attribution
North Korea (RGB Bureau 121)
Motivation
Financial, Espionage, Sabotage
Modus Operandi (MO)
Cryptocurrency heists, SWIFT banking attacks, supply chain compromise, espionage, ransomware
Primary Aliases
HIDDEN COBRA, Guardians of Peace, ZINC, APT38, BlueNoroff, Andariel

Lazarus Group is North Korea's most prominent and prolific state-sponsored cyber threat actor, attributed to the Reconnaissance General Bureau (RGB), specifically Bureau 121, North Korea's primary cyber warfare unit. Active since at least 2009, Lazarus is unique among nation-state APTs in that a significant portion of its operations are explicitly designed to generate hard currency revenue for the Kim Jong-un regime, which faces severe international economic sanctions.

The group is responsible for some of the most financially damaging cyberattacks ever recorded. The 2016 Bangladesh Bank SWIFT heist saw Lazarus steal $81 million USD through fraudulent inter-bank transfer instructions. Their cryptocurrency theft operations have stolen an estimated $3 billion USD worth of digital assets over the past several years, with a single 2022 attack on the Ronin Network yielding $625 million USD , the largest cryptocurrency theft in history at the time.

Beyond financial crime, Lazarus conducts traditional cyber espionage targeting defence contractors, government agencies, and think tanks across the United States, South Korea, Japan, and Europe. The group has deployed destructive wiper malware against targets in South Korea and was responsible for the devastating Sony Pictures Entertainment hack in 2014, which destroyed thousands of computers and leaked sensitive corporate data in retaliation for the film "The Interview."

Lazarus maintains multiple sub-groups with specialised functions: BlueNoroff focuses exclusively on financial institution targeting, while Andariel primarily conducts South Korea-focused espionage and ransomware operations. The group continuously evolves its tactics and malware to evade detection, representing a sustained, persistent, and dangerous threat to the global financial system and national security interests worldwide.

Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Lazarus Group requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles