Lazarus Group is a North Korea-linked threat actor broadly assessed to operate on behalf of the Democratic People's Republic of Korea and commonly associated with the Reconnaissance General Bureau. It is one of the most prolific and diverse state-sponsored cyber operators, conducting espionage, financially motivated theft, supply-chain compromise, and occasionally disruptive or destructive operations. Widely used aliases include Hidden Cobra, Zinc, Diamond Sleet, Sapphire Sleet, APT-C-26, Guardians of Peace, Labyrinth Chollima, Stardust Chollima, Nickel Academy, Nickel Gladstone, Nickel Tapestry, TA404, UNC1069, and related sub-clusters such as BlueNoroff and APT38. Reporting also links campaign names and sub-operations including Contagious Interview, PolinRider, AppleJeus, Operation Dream Job, and other developer- and cryptocurrency-focused activity to the broader Lazarus ecosystem. The group targets governments, defense organizations, aerospace and drone manufacturers, software developers, cryptocurrency businesses, blockchain platforms, financial institutions, and critical infrastructure. A persistent theme is revenue generation for the North Korean regime through cryptocurrency theft and intrusion activity against digital-asset organizations, while parallel operations support intelligence collection and strategic access. Lazarus has also repeatedly targeted individual developers and job seekers, especially through fake recruiter and coding-test lures, as well as software supply chains where compromise of a maintainer account or repository can cascade into downstream victim environments. Its tradecraft is adaptable and spans social engineering, spearphishing, recruiter impersonation, malicious job offers, trojanized coding challenges, typosquatted packages, poisoned open-source dependencies, compromised source-code repositories, and supply-chain abuse across developer ecosystems. Recent activity attributed to Lazarus-linked clusters includes compromise of GitHub repositories and package ecosystems through injected obfuscated JavaScript loaders, malicious configuration-file modifications, abuse of VS Code task execution, fake font-file payload concealment, and use of blockchain-based dead drops for payload staging. Contagious Interview operations have used trojanized developer projects that reconstruct malware from steganographically hidden fragments and execute it when the victim runs the local application. Lazarus-linked operators have also been associated with fake business meetings, fraudulent job opportunities, and social-engineering campaigns aimed at cryptocurrency and technology personnel. Malware and tooling associated with Lazarus and its sub-groups include families such as Beavertail, InvisibleFerret, OTTERCOOKIE, WAVESHAPER, and AppleJeus-related implants, along with a wide range of custom loaders, stealers, backdoors, and remote-access tooling. Observed capabilities include browser credential theft, cryptocurrency wallet theft, cloud and developer-secret harvesting, file exfiltration, clipboard monitoring, remote shell access, and persistence through common Windows autostart mechanisms such as Registry Run keys and Startup folders. Lazarus malware has also demonstrated victim filtering based on system language or locale in some operations. The group frequently uses living-off-the-land techniques, legitimate cloud or collaboration services, and cross-platform tooling spanning Windows and macOS. BlueNoroff and APT38 are commonly treated as Lazarus-affiliated financial operations focused on cryptocurrency theft and financial compromise. BlueNoroff has been tied to long-running campaigns against the cryptocurrency ecosystem, including fake investment, hiring, and business-contact lures, and has targeted both macOS and Windows environments. APT38 is widely associated with financially motivated operations and cryptocurrency theft at scale. Contagious Interview appears to function as a Lazarus-aligned developer-targeting cluster centered on social engineering and malware delivery through coding tests and software-development workflows. PolinRider has been described as a Lazarus-linked supply-chain campaign and as a parallel or subordinate campaign to Contagious Interview, focused on compromising developer repositories and package ecosystems. Lazarus Group remains notable for combining nation-state espionage priorities with aggressive criminal-style monetization. Its operations routinely blend stealth, persistence, credential theft, supply-chain compromise, and social engineering, making it one of the most operationally versatile and strategically significant threat actors in the global cyber landscape.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
69 malware families attributed to this actor across reporting.
64 additional families tracked in Mallory.
14 CVEs this actor has used in observed campaigns. 14 of them exploited in the wild.
Enterprise T1203 Exploitation for Client Execution Lazarus Group has exploited Adobe Flash vulnerability CVE-2018-4878 for execution.
"APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析" published by Qihoo360.
WannaCry emerged on May 12, 2017 by exploiting a vulnerability in the SMBv1 protocol of Microsoft Windows (CVE-2017-0144 aka EternalBlue). This vulnerability, which was addressed by the Microsoft security patch MS17-010 in March 2017, allowed remote code execution without authentication.
In December 2023, Lazarus Group continued to exploit the notorious Log4Shell vulnerability (CVE-2021-44228), specifically targeting unpatched VMware Horizon servers.
Lazarus was also observed leveraging CVE-2022-0609, a 0-day remote code execution vulnerability in Google Chrome web browser to target cryptocurrency and fintech entities through spearphishing, fake websites, or compromised legitimate websites.
9 more CVEs tied to this actor tracked in Mallory.
1,948 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in connection with a report about a North Korean hacker allegedly hired by Consensys; the specific operational activity or campaign is not described in the provided content.
North Korean state cyber actor responsible for major cryptocurrency thefts and targeted operations against European drone and defense component manufacturers; AppleJeus branch specializes in crypto theft and was behind the 3CX supply-chain attack.
Campaign using fake job offers and trojanized coding challenge repositories delivered via Slack to infect developers, followed by credential theft, file theft, persistent C2 access, clipboard theft, and secondary payload delivery.
A DPRK-aligned fake job/coding test campaign targeting developers by distributing trojanized repositories that reconstruct and execute malware from SVG comment fragments, enabling credential theft, crypto wallet theft, file theft, remote access, and clipboard monitoring on Windows systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.