Lazarus Group is a North Korean state-backed threat actor associated with espionage, financially motivated operations, and large-scale cryptocurrency theft. It is also tracked as Hidden Cobra, Diamond Sleet, ZINC, APT38, Labyrinth Chollima, Guardians of Peace, Nickel Academy, and UNC2970. The group is known for social-engineering operations, including fake recruitment and job-offer lures, to gain initial access to targets. It has targeted cryptocurrency platforms and professionals, and has conducted supply-chain-style compromises to manipulate high-value cryptocurrency transactions. Lazarus has also targeted aerospace and defense organizations through Operation Dream Job, using malicious software delivered with job lures and exploitation of a Windows privilege-escalation vulnerability to obtain SYSTEM-level access. The group has used custom tooling and legitimate cloud-storage services, including Dropbox, for data exfiltration. Its operations encompass credential theft, reconnaissance, persistence, privilege escalation, data theft, and cryptocurrency theft. Lazarus activity supports North Korean strategic interests and is widely associated with efforts to generate revenue despite international sanctions, alongside traditional intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
83 malware families attributed to this actor across reporting.
78 additional families tracked in Mallory.
35 CVEs this actor has used in observed campaigns. 35 of them exploited in the wild.
Today, August 25, 2026, is the CISA KEV deadline requiring all Federal Civilian Executive Branch agencies to patch CVE-2026-68820, the underlying Windows WinSock driver flaw that ShieldBreak (CVE-2026-69414) bypasses. Check Point Research this week formally attributed exploitation of CVE-2026-68820 to North Korea's Lazarus Group as part of Operation Dream Job, where the group distributed a malicious PDF viewer called SecurityPDF to aerospace and defence targets alongside fake job offer lures, using the driver flaw to escalate from initial access to full SYSTEM privileges.
Lazarus compromet des installations Roundcube et des CMS vulnérables à CVE-2025-49113, en utilisant des identifiants issus de fuites sur le dark web.
In early June, we discovered a sample that was exploiting a new zero-day vulnerability within Winsock driver ( CVE-2024-38193 ) to achieve local privilege escalation to deploy a new version of FudModule rootkit.
Together they form a re-packaged exploit for Silverlight based on CVE-2016-0034 (MS16-006) – a Silverlight Memory Corruption vulnerability. The exploit has previously been used by several exploit kits including RIG and Angler to deliver multiple crimeware tools.
The group is known for spearphishing attacks, which include CVE-2015-6585, a zero-day vulnerability at the time of its discovery.
30 more CVEs tied to this actor tracked in Mallory.
5,350 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Documented conducting fake-recruiter campaigns that use fake job offers and a remote-access backdoor.
Referenced in connection with North Korean hackers moving tens of millions through the Hyperliquid cryptocurrency platform.
Used the Hyperliquid cryptocurrency platform; the referenced activity may expose the platform to U.S. sanctions-law scrutiny.
Cited as using a customized dbxcli utility with Dropbox for cloud-based data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.