Lazarus Group is a North Korea-linked threat actor broadly associated with the Democratic People's Republic of Korea and widely assessed to operate in support of state objectives, including espionage, disruptive operations, and large-scale financially motivated cybercrime. The group is one of the most prolific and diverse DPRK cyber actors and has been tracked under numerous aliases, including Hidden Cobra, Zinc, Diamond Sleet, Labyrinth Chollima, Stardust Chollima, Famous Chollima, Nickel Academy, Nickel Gladstone, Nickel Tapestry, TA404, UNC1069, and other cluster names used by different vendors. Public reporting also frequently discusses related or overlapping sub-clusters and affiliates such as BlueNoroff/APT38, Contagious Interview, DEV#POPPER, and PolinRider. Lazarus has targeted a wide range of sectors worldwide, including cryptocurrency exchanges and decentralized finance organizations, financial institutions, software developers, technology companies, defense organizations, government entities, healthcare, research institutions, and cybersecurity professionals. A defining characteristic of the actor is its dual use of espionage tradecraft and revenue-generation operations. Financially motivated activity has been especially prominent in campaigns against cryptocurrency businesses, wallet holders, blockchain projects, and Web3 developers, with theft and laundering of digital assets repeatedly linked to DPRK strategic funding objectives. The group is well known for aggressive social engineering. It routinely impersonates recruiters, hiring managers, business partners, researchers, or fellow security professionals to build trust and induce victims to open malicious projects, install trojanized software, or execute commands during fake interviews or collaboration workflows. Developer-focused operations have used malicious GitHub repositories, npm packages, typosquatted or brand-jacking packages, poisoned dependencies, fake code reviews, and compromised maintainer accounts. Job-themed campaigns such as Contagious Interview have targeted software engineers and cryptocurrency professionals with interview lures that deliver malware across Windows, macOS, and Linux. Lazarus has also demonstrated strong supply-chain capability. Reported operations include compromise of open-source ecosystems and package registries, malicious dependency injection, takeover of legitimate repositories, and publication of trojanized packages that execute at import time or through development tooling. In repo-sourced ecosystems, the actor has exploited the trust relationship between source repositories and downstream package consumption. Associated campaigns have used obfuscated JavaScript loaders, malicious configuration-file injections, IDE task abuse, and hidden payloads embedded in non-obvious artifacts. Malware and tooling associated with Lazarus-linked activity include BeaverTail, InvisibleFerret, DEV#POPPER, OmniStealer, QuiteRAT, and other custom loaders, stealers, backdoors, and downloader chains. These toolsets commonly focus on credential theft, browser data theft, cryptocurrency wallet theft, keychain or password-store access, remote command execution, file exfiltration, and deployment of follow-on implants. Some Lazarus operations have used malware delivered as source code that is compiled on the victim host, while others have relied on in-memory execution, process injection, shellcode loaders, or abuse of legitimate runtimes such as Node.js, Python, and Go. The actor regularly abuses legitimate services and trusted platforms for delivery, command and control, staging, and exfiltration. Reported Lazarus tradecraft includes use of GitHub, cloud storage providers, collaboration platforms, package registries, messaging applications, and blockchain-based dead-drop mechanisms. Recent campaigns have shown particular interest in hiding payload pointers or encrypted stages in public blockchain transaction data, complicating takedown and detection. Lazarus has also used stealth techniques such as anti-dated commits, force-pushed history rewrites, obfuscation, sandbox evasion, delayed execution, and concealment of malicious logic in metadata or extended file attributes on macOS. On endpoints, Lazarus has employed a broad range of persistence and execution methods, including Registry Run keys, Startup folder shortcuts, LaunchAgents on macOS, malicious extensions, trojanized installers, and abuse of development environments such as Visual Studio Code and Cursor. The group has also used process injection, suspended-process creation, remote thread execution, and fileless or memory-resident payload stages. Victim profiling commonly includes collection of host identifiers, operating system details, language settings, installed software, browser data, and cryptocurrency wallet artifacts, sometimes with locale checks to avoid or refine targeting. Lazarus has additionally been linked to exploitation of public-facing applications and older but still unpatched vulnerabilities to gain footholds and maintain long-term access. Reported activity includes exploitation of enterprise software and internet-facing services followed by deployment of remote access tooling for surveillance, persistence, and lateral movement. In parallel with these intrusion methods, the broader DPRK ecosystem tied to Lazarus has been associated with false-identity employment schemes in which operators seek remote jobs to obtain insider access to source code, cloud environments, and corporate networks. Overall, Lazarus Group represents a mature, adaptive, and strategically significant DPRK cyber capability distinguished by its blend of espionage, supply-chain compromise, developer targeting, and cryptocurrency theft. Its operations consistently show strong operational flexibility across platforms, heavy reliance on social engineering, and sustained focus on monetization in support of North Korean state interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
68 malware families attributed to this actor across reporting.
63 additional families tracked in Mallory.
14 CVEs this actor has used in observed campaigns. 14 of them exploited in the wild.
Enterprise T1203 Exploitation for Client Execution Lazarus Group has exploited Adobe Flash vulnerability CVE-2018-4878 for execution.
"APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析" published by Qihoo360.
WannaCry emerged on May 12, 2017 by exploiting a vulnerability in the SMBv1 protocol of Microsoft Windows (CVE-2017-0144 aka EternalBlue). This vulnerability, which was addressed by the Microsoft security patch MS17-010 in March 2017, allowed remote code execution without authentication.
In December 2023, Lazarus Group continued to exploit the notorious Log4Shell vulnerability (CVE-2021-44228), specifically targeting unpatched VMware Horizon servers.
Lazarus was also observed leveraging CVE-2022-0609, a 0-day remote code execution vulnerability in Google Chrome web browser to target cryptocurrency and fintech entities through spearphishing, fake websites, or compromised legitimate websites.
9 more CVEs tied to this actor tracked in Mallory.
1,925 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Distributed malicious npm packages using brand-jacking and typosquatting techniques.
Referenced as a known threat group whose TTPs were emulated by AI agents in a study assessing whether TTP-based attribution can be undermined.
Conducting a DPRK-linked supply-chain campaign dubbed PolinRider by compromising legitimate GitHub accounts, force-pushing malicious commits into repositories, and leveraging repo-backed ecosystems such as Go modules and Packagist to distribute malware at scale.
Referenced in connection with blockchain security and anti-money laundering discussion; no specific operation or activity is described in the content itself.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.