Cyber overview
Cyber threat actor

Lazarus Group

North Korean state-sponsored (Reconnaissance General Bureau) · active since 2009

Regime-directed group combining espionage, destructive attacks (Sony Pictures), and large-scale cryptocurrency theft to fund sanctioned weapons programs.

Aliases
Hidden CobraDiamond SleetAPT38
Primary targets
Cryptocurrency exchanges Defense contractors Media/entertainment Financial institutions

MITRE ATT&CK techniques

0 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

No MITRE ATT&CK mapping available yet for Lazarus Group.

Curated incidents

  1. 2022-04-01·Financial / Cryptocurrency·Global (US exchanges affected)
    DOJ seizes cryptocurrency stolen by Lazarus Group in Axie Infinity hack

    North Korean operators stole roughly $620 million from the Ronin bridge; US Treasury sanctions wallet addresses tied to the group.