Lazarus Group
Also tracked as Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.
- Documented techniques
- 93
- Assessed origin
- North Korea
- Assessed motivation
- Espionage, Financial gain
- First seen
- 2009
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance2
resource development8
initial access4
execution8
persistence4
discovery11
- T1010 Application Window Discovery
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1033 System Owner/User Discovery
- T1046 Network Service Discovery
- T1049 System Network Connections Discovery
- T1057 Process Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1124 System Time Discovery
- T1680 Local Storage Discovery
collection6
command and control11
- T1001.003 Protocol or Service Impersonation
- T1008 Fallback Channels
- T1071.001 Web Protocols
- T1090.001 Internal Proxy
- T1090.002 External Proxy
- T1102.002 Bidirectional Communication
- T1104 Multi-Stage Channels
- T1105 Ingress Tool Transfer
- T1132.001 Standard Encoding
- T1571 Non-Standard Port
- T1573.001 Symmetric Cryptography
exfiltration2
impact6
defense impairment3
stealth23
- T1027.007 Dynamic API Resolution
- T1027.009 Embedded Payloads
- T1027.013 Encrypted/Encoded File
- T1036.003 Rename Legitimate Utilities
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1055.001 Dynamic-link Library Injection
- T1070 Indicator Removal
- T1070.003 Clear Command History
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1078 Valid Accounts
- T1134.002 Create Process with Token
- T1140 Deobfuscate/Decode Files or Information
- T1202 Indirect Command Execution
- T1218 System Binary Proxy Execution
- T1218.005 Mshta
- T1218.011 Rundll32
- T1542.003 Bootkit
- T1564.001 Hidden Files and Directories
- T1574.001 DLL
- T1574.013 KernelCallbackTable
- T1620 Reflective Code Loading
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.