G0032: Lazarus Group
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). CitationUS-CERT HIDDEN COBRA June 2017 CitationTreasury North Korean Cyber Groups September 2019 Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.CitationNovetta Blockbuster
North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.CitationMandiant DPRK Laz Org Breakdown 2022CitationMandiant DPRK Groups 2023CitationJPCert Blog Laz Subgroups 2025
Security context for executives and security teams
Lazarus Group is an ATT&CK intrusion set used as an umbrella for North Korean cyber activity associated in public reporting with espionage, destructive attacks, and financially motivated campaigns. For leaders, the practical issue is not the name itself but the breadth: related ATT&CK relationships include multiple remote access tools, backdoors, destructive or ransomware-related tooling, network utilities, and a campaign affecting defense, aerospace, government, financial, and other sectors. Treat this as a test of whether your organization can connect threat intelligence, endpoint/network telemetry, identity evidence, and recovery planning across long-running, multi-tool operations.
Executive priority
Prioritize this object when assessing resilience against state-linked activity, destructive malware scenarios, financial fraud risk, and high-value-sector exposure. Executives should ask whether incident response plans distinguish espionage, ransomware/destructive activity, and business email compromise decisions; whether Windows, macOS, and Linux monitoring gaps are known; and whether audit evidence can show patching, segmentation, privileged access control, and recovery readiness. Because ATT&CK notes attribution challenges and shared DPRK personnel, infrastructure, malware, and tradecraft, leadership should avoid over-focusing on actor naming and instead fund behavior-based detection and response capabilities.
Technical view
ATT&CK provides no official detection text, tactics, or platforms for the group object itself, so SOC and IR teams should validate coverage through the related software and campaign context. Relationships point to Windows-heavy malware and tools such as Volgmer, FALLCHILL, Bankshot, RATANKBA, BADCALL, HARDRAIN, TYPEFRAME, KEYMARBLE, AuditCred, RawDisk, WannaCry, HOPLIGHT, HotCroissant, BLINDINGCAN, Dtrack, and others, plus macOS/Linux exposure through Dacls and macOS exposure through Cryptoistic and AppleJeus. Defensive validation should emphasize remote access tooling, suspicious DLL execution, backdoor persistence, raw disk access, SMB/worm-like propagation risk, route/netsh changes, and LLMNR/NBT-NS/mDNS poisoning or rogue authentication behavior associated with Responder.
Likely telemetry
- Endpoint process, module/DLL load, service, persistence, and file-write telemetry, especially on Windows and where macOS/Linux assets are in scope from related software
- Network connection, DNS, proxy, web, and command-and-control style beaconing evidence for RATs and backdoors
- Windows command and script logging for netsh and route usage, including local or remote network configuration changes
- Authentication telemetry, NTLM events, SMB activity, and name-resolution traffic relevant to Responder-style credential capture
- Email and collaboration logs where Operation Dream Job or suspected spearphishing/BEC-adjacent activity is a relevant business concern
Detection direction
- Do not rely on the actor label as the detection strategy; map alerts to related malware/tool behaviors and local asset criticality.
- Validate coverage for Windows first because many related software entries specify Windows, then explicitly test macOS and Linux visibility where Dacls, Cryptoistic, or AppleJeus-like relationships matter.
- Tune for suspicious use of legitimate administration/network utilities such as netsh and route by correlating command context, user, host role, and change window to reduce false positives.
- Hunt for rogue authentication and name-resolution abuse patterns, especially LLMNR/NBT-NS/mDNS and NTLM capture indicators, where Responder exposure is possible.
- Correlate RAT/backdoor detections with outbound network patterns, persistence changes, and credential events rather than single indicators alone.
Mitigation priorities
- Sequence controls around resilience: patch and reduce exposed legacy SMB risk, harden endpoint execution, and maintain tested offline or protected backups.
- Reduce credential theft paths by disabling unnecessary name-resolution protocols where feasible, hardening NTLM usage, and monitoring authentication anomalies.
- Apply least privilege and privileged access controls so RAT or backdoor access does not automatically become domain-wide control.
- Segment high-value business, financial, engineering, and any OT/ICS-adjacent environments to limit propagation and destructive impact.
- Maintain cross-platform endpoint monitoring where macOS and Linux assets are present, not only Windows-focused defenses.
Additional notes and limits
ATT&CK describes Lazarus Group as a North Korean state-sponsored group attributed to the RGB and notes that public reporting often uses the name as an umbrella for multiple North Korean operators. That matters analytically: shared infrastructure, malware, personnel, and tradecraft can make precise attribution difficult. Relationships to many software objects provide useful defensive validation points, but local telemetry and incident evidence are required before making environment-specific conclusions.
The group object has no official ATT&CK detection guidance, tactics, or platforms. Platform and behavior observations here are inferred only from supplied relationships to software and campaign objects, not from a complete procedure list. This take does not assert current exploitation, customer exposure, guaranteed detection, or definitive attribution for any local incident.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Lazarus Group
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). CitationUS-CERT HIDDEN COBRA June 2017 CitationTreasury North Korean Cyber Groups September 2019 Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.CitationNovetta Blockbuster
North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.CitationMandiant DPRK Laz Org Breakdown 2022CitationMandiant DPRK Groups 2023CitationJPCert Blog Laz Subgroups 2025
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
