Lazarus Group is a North Korea-linked threat actor broadly associated with the Democratic People's Republic of Korea and widely assessed to operate in support of state objectives, including espionage, disruptive operations, and large-scale financially motivated cybercrime. The group is known under numerous aliases, including Hidden Cobra, Zinc, Diamond Sleet, Labyrinth Chollima, Stardust Chollima, Guardians of Peace, Nickel Academy, Nickel Gladstone, Storm-0139, Storm-0954, Storm-1222, UNC1069, UNC1720, Black Artemis, and Copernicium. Reporting also frequently distinguishes related or overlapping clusters and subgroups such as APT38, BlueNoroff, and Famous Chollima, though naming and subgroup boundaries vary by vendor. Lazarus has targeted governments, defense organizations, financial institutions, cryptocurrency exchanges, decentralized finance platforms, software developers, technology companies, healthcare entities, internet service providers, and job seekers. A defining characteristic is the combination of strategic intelligence collection with revenue-generation operations that support the North Korean regime. The actor has been repeatedly linked to cryptocurrency theft, wallet compromise, exchange intrusions, and laundering activity, while also conducting classic espionage against regional and international targets. The group is especially notable for sophisticated social engineering. It has run long-running job-themed operations such as Operation Dream Job and Contagious Interview, impersonating recruiters, employers, or interview platforms to lure victims into executing malware. These campaigns have targeted developers, cryptocurrency professionals, and security personnel through fake job offers, code review requests, trojanized projects, and staged interview workflows. Lazarus has also used private messaging platforms, social networks, and developer ecosystems to build trust and deliver payloads. Lazarus has demonstrated strong supply-chain tradecraft. It has distributed malicious and typosquatted packages in open-source ecosystems and has been linked to campaigns that compromise legitimate maintainer accounts and backdoor trusted repositories and packages. Recent activity associated with the PolinRider cluster shows expansion beyond a single package ecosystem into repo-sourced software distribution channels, with malicious code hidden in configuration files, editor task files, fake asset files, and dependencies. In these operations, the actor has used anti-forensic techniques such as force-pushed and backdated commits to conceal tampering and make malicious changes appear routine. Malware and tooling associated with Lazarus include BeaverTail, InvisibleFerret, DEV#POPPER, OmniStealer, QuiteRAT, and other custom loaders, stealers, backdoors, and remote access tools. The group has also used Go-, JavaScript-, Python-, shell-, and VBS-based components, and has shown the ability to compile or execute source-delivered implants directly on victim systems. Observed capabilities include credential theft, browser and wallet theft, developer-secret theft, host profiling, remote command execution, file upload and download, screenshot capture, process management, and long-term persistence. The actor regularly abuses legitimate services and public infrastructure for delivery, command and control, and exfiltration. Reported operations have leveraged cloud storage providers, developer platforms, OAuth-enabled services, and public blockchain networks as resilient dead-drop or payload-delivery channels. Lazarus has also used stealth techniques such as in-memory execution, process injection, encrypted staging, obfuscated JavaScript loaders, and concealment of malicious data in macOS extended file attributes, a technique publicly described as RustyAttr. On victim hosts, Lazarus commonly performs extensive discovery and environment validation. Reported behaviors include collecting operating system type and version, computer name, CPU details, disk information, installed software, and registry-based configuration data. Some Lazarus malware checks language or locale settings and may avoid execution on systems configured for certain East Asian languages. The group has also used Windows persistence mechanisms such as Registry Run keys and Startup folder artifacts, including LNK-based persistence in job-themed campaigns. Lazarus has also exploited public-facing vulnerabilities to gain or maintain access. Reported activity includes exploitation of CVE-2021-44228 and CVE-2022-47966 to compromise enterprise systems and deploy remote access tooling for surveillance and follow-on operations. This complements the group's more human-centric intrusion methods and shows operational flexibility across initial access vectors. Overall, Lazarus Group is one of the most prolific and adaptable state-linked threat actors in operation. Its tradecraft spans espionage, destructive activity, software supply-chain compromise, developer targeting, and high-value cryptocurrency theft, with a persistent emphasis on stealth, operational resilience, and monetization in support of North Korean strategic interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
34 malware families attributed to this actor across reporting.
29 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
In December 2023, Lazarus Group continued to exploit the notorious Log4Shell vulnerability (CVE-2021-44228), specifically targeting unpatched VMware Horizon servers.
In early 2023, Lazarus Group targeted CVE-2022-47966, a vulnerability in ManageEngine ServiceDesk Plus, which allowed them to execute arbitrary code on unpatched systems.
206 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Distributed malicious npm packages using brand-jacking and typosquatting techniques.
Referenced as a known threat group whose TTPs were emulated by AI agents in a study assessing whether TTP-based attribution can be undermined.
Conducting a DPRK-linked supply-chain campaign dubbed PolinRider by compromising legitimate GitHub accounts, force-pushing malicious commits into repositories, and leveraging repo-backed ecosystems such as Go modules and Packagist to distribute malware at scale.
Referenced in connection with blockchain security and anti-money laundering discussion; no specific operation or activity is described in the content itself.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.