Lazarus Group is a North Korean state-linked threat actor umbrella associated with both espionage and financially motivated cyber operations conducted in support of the DPRK. It is widely tracked under numerous aliases including Hidden Cobra, Zinc, Diamond Sleet, Coral Sleet, Labyrinth Chollima, Stardust Chollima, Famous Chollima, TA404, UNC1069, and Guardians of Peace, although several of these names are used by vendors to describe specific sub-clusters or mission sets rather than the entire organization. Reporting commonly treats Lazarus as a broader ecosystem that includes distinct but related operational elements focused on cyber espionage, cryptocurrency theft, software supply-chain compromise, and fraudulent remote-work infiltration. The actor has targeted cryptocurrency exchanges, fintech firms, blockchain projects, software developers, defense and aerospace organizations, manufacturers, logistics and shipping companies, government-related entities, and critical infrastructure. A persistent theme is the use of employment and recruiter luses to gain execution on victim systems or to place operatives inside target organizations. Long-running campaigns such as Operation DreamJob and Contagious Interview have used fake job offers, coding tests, trojanized development projects, malicious npm and Python packages, ClickFix-style terminal pastes, and Git-hook abuse to compromise developers and professionals in cryptocurrency, Web3, defense, and related sectors. Lazarus-linked operations have repeatedly demonstrated strong software supply-chain tradecraft. Recent activity attributed to UNC1069 involved compromise of widely used npm packages through stolen maintainer credentials and malicious dependency insertion, delivering cross-platform backdoors associated with the WAVESHAPER malware lineage. Other Lazarus-linked developer-focused campaigns have hidden loaders in postinstall scripts, Visual Studio Code tasking, fake assets, and Git hooks to trigger early in the development workflow. The group has also used trojanized legitimate software, malicious open-source packages, and CI/CD abuse to reach downstream victims at scale. Malware and tooling associated with Lazarus and its sub-groups include WAVESHAPER, Hoplight-lineage malware, FudModule, Jeus and AppleJeus, InvisibleFerret-style implants, PylangGhost, GolangGhost, Scuzzyfuss, TwoPence Electric, SnakeBaker, NodalBaker, and other custom loaders, stealers, and remote access tools. Tradecraft observed across these operations includes credential theft, browser and wallet extension harvesting, persistence via platform-native mechanisms, encrypted command-and-control, cloud and container discovery, social engineering through professional networking platforms and messaging apps, and use of zero-days or vulnerable drivers for stealth and privilege escalation in some clusters. Multiple vendor tracking schemes describe Lazarus as comprising specialized sub-groups. Financially motivated elements have been associated with large-scale cryptocurrency theft and laundering activity, while espionage-focused elements have concentrated on defense, manufacturing, aerospace, and strategic intelligence collection. Famous Chollima has been linked to fake interview campaigns targeting cryptocurrency and Web3 professionals, including delivery of GolangGhost and PylangGhost. Labyrinth Chollima has been associated more narrowly with espionage operations using Hoplight-lineage malware and employment-themed lures against defense and industrial targets. UNC1069 has been tied to DPRK-attributed supply-chain compromises and WAVESHAPER-related malware. These distinctions vary by vendor, but the clusters are generally assessed as interconnected components of the broader DPRK cyber apparatus. Lazarus is also associated with North Korea’s use of fraudulent IT workers and false identities to infiltrate remote hiring pipelines, particularly in the cryptocurrency sector. Such operations are intended to generate revenue, obtain insider access, and create opportunities for follow-on theft or espionage. Overall, Lazarus Group remains one of the most capable and adaptable state-linked cyber threats, combining strategic intelligence collection with aggressive revenue-generation operations that support the North Korean regime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
64 malware families attributed to this actor across reporting.
59 additional families tracked in Mallory.
14 CVEs this actor has used in observed campaigns. 14 of them exploited in the wild.
Enterprise T1203 Exploitation for Client Execution Lazarus Group has exploited Adobe Flash vulnerability CVE-2018-4878 for execution.
"APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析" published by Qihoo360.
WannaCry emerged on May 12, 2017 by exploiting a vulnerability in the SMBv1 protocol of Microsoft Windows (CVE-2017-0144 aka EternalBlue). This vulnerability, which was addressed by the Microsoft security patch MS17-010 in March 2017, allowed remote code execution without authentication.
In December 2023, Lazarus Group continued to exploit the notorious Log4Shell vulnerability (CVE-2021-44228), specifically targeting unpatched VMware Horizon servers.
Lazarus was also observed leveraging CVE-2022-0609, a 0-day remote code execution vulnerability in Google Chrome web browser to target cryptocurrency and fintech entities through spearphishing, fake websites, or compromised legitimate websites.
9 more CVEs tied to this actor tracked in Mallory.
2,045 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting fake job interview social-engineering campaigns targeting cryptocurrency and Web3 professionals, delivering PylangGhost to Windows users and GolangGhost to macOS users to steal credentials, wallet data, and gain remote access.
North Korean threat actor conducting fake job-offer lure campaigns against European defence and drone manufacturers as part of Operation DreamJob.
Only indirectly referenced via the account name 'lazarusholic'; the content itself is about North Korean IT workers infiltrating remote hiring, not a specific named threat actor group.
The group is described as deploying remote access trojans through ClickFake job interview lures.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.