Lazarus Group is a North Korea-linked threat actor widely associated with long-running espionage, financially motivated operations, disruptive activity, and software supply-chain compromise. The group is commonly tracked under the name Lazarus Group and is part of the broader DPRK cyber apparatus; reporting and vendor nomenclature sometimes distinguish related clusters and sub-groups such as APT38, which is frequently associated with financially motivated operations. Lazarus Group has targeted governments, defense organizations, cryptocurrency and blockchain ecosystems, financial institutions, software developers, and security professionals. Its operations regularly combine social engineering with malware deployment, credential theft, and abuse of trusted platforms and developer ecosystems. Known tradecraft includes phishing and recruiter-style lures, trojanized software and packages, brand impersonation, typosquatting, supply-chain compromise, and use of legitimate cloud and collaboration services to blend command-and-control, payload delivery, and exfiltration into normal traffic. In developer-focused campaigns, Lazarus Group has been observed distributing brand-jacking and typosquatting packages through npm to reach downstream victims via software dependency chains. More broadly, North Korea-linked operators associated with this ecosystem have used platforms such as code repositories, cloud storage, online documents, and developer tooling to target developers, cryptocurrency professionals, and information security personnel. These campaigns reflect a sustained emphasis on initial access through trusted services, theft of credentials and tokens, and compromise of software supply chains. The group is notable for operational adaptability and for shifting beyond traditional malware-only intrusions toward account theft, token abuse, cloud exploitation, and stealthier use of legitimate services. Lazarus Group remains one of the most active and strategically significant state-linked threat actors, with activity aligned to North Korean intelligence collection and revenue-generation objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.