93
Techniques
26
Toolsets
0
CVEs Referenced
0
KEV Entries
About Lazarus Group

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.

View MITRE record ↗

Techniques by Tactic (93)
Toolsets (26)
🐛
AppleJeus S0584
Malware · Windows, macOS
🐛
AuditCred S0347
Malware · Windows
🐛
BADCALL S0245
Malware · Windows
🐛
Malware · Windows
🐛
Bankshot S0239
Malware · Windows
🐛
Malware · macOS
🐛
Dacls S0497
Malware · macOS, Linux, Windows
🐛
Dtrack S0567
Malware · Windows
🐛
Malware · Windows
🐛
FALLCHILL S0181
Malware · Windows
🐛
HARDRAIN S0246
Malware · Windows
🐛
HOPLIGHT S0376
Malware · Windows
🐛
Malware · Windows
🐛
KEYMARBLE S0271
Malware · Windows
🐛
MagicRAT S1182
Malware · Windows
🐛
Proxysvc S0238
Malware · Windows
🐛
RATANKBA S0241
Malware · Windows
🐛
Malware · Windows
🐛
TYPEFRAME S0263
Malware · Windows
🐛
Malware · Windows
🐛
Volgmer S0180
Malware · Windows
🐛
WannaCry S0366
Malware · Windows
🔧
RawDisk S0364
Tool · Windows
🔧
Responder S0174
Tool
🔧
netsh S0108
Tool · Windows
🔧
route S0103
Tool
References & Reports (11)
↑