> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
LAZARUS GROUP
/actor/lazarus-group/ · 0 intel reports
Lazarus Group is North Korea's most prominent and prolific state-sponsored cyber threat actor, attributed to the Reconnaissance General Bureau (RGB), specifically Bureau 121, North Korea's primary cyber warfare unit. Active since at least 2009, Lazarus is unique among nation-state APTs in that a significant portion of its operations are explicitly designed to generate hard currency revenue for the Kim Jong-un regime, which faces severe international economic sanctions.
The group is responsible for some of the most financially damaging cyberattacks ever recorded. The 2016 Bangladesh Bank SWIFT heist saw Lazarus steal $81 million USD through fraudulent inter-bank transfer instructions. Their cryptocurrency theft operations have stolen an estimated $3 billion USD worth of digital assets over the past several years, with a single 2022 attack on the Ronin Network yielding $625 million USD , the largest cryptocurrency theft in history at the time.
Beyond financial crime, Lazarus conducts traditional cyber espionage targeting defence contractors, government agencies, and think tanks across the United States, South Korea, Japan, and Europe. The group has deployed destructive wiper malware against targets in South Korea and was responsible for the devastating Sony Pictures Entertainment hack in 2014, which destroyed thousands of computers and leaked sensitive corporate data in retaliation for the film "The Interview."
Lazarus maintains multiple sub-groups with specialised functions: BlueNoroff focuses exclusively on financial institution targeting, while Andariel primarily conducts South Korea-focused espionage and ransomware operations. The group continuously evolves its tactics and malware to evade detection, representing a sustained, persistent, and dangerous threat to the global financial system and national security interests worldwide.
Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Lazarus Group requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.