Cyber threat actor
Lazarus Group
North Korean state-sponsored (Reconnaissance General Bureau) · active since 2009
Regime-directed group combining espionage, destructive attacks (Sony Pictures), and large-scale cryptocurrency theft to fund sanctioned weapons programs.
Aliases
Hidden CobraDiamond SleetAPT38
Primary targets
Cryptocurrency exchanges Defense contractors Media/entertainment Financial institutions
MITRE ATT&CK techniques
0 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
No MITRE ATT&CK mapping available yet for Lazarus Group.
Curated incidents
- 2022-04-01·Financial / Cryptocurrency·Global (US exchanges affected)DOJ seizes cryptocurrency stolen by Lazarus Group in Axie Infinity hack
North Korean operators stole roughly $620 million from the Ronin bridge; US Treasury sanctions wallet addresses tied to the group.