ATT&CKGroupsLazarus Group

Lazarus Group

G0032

Threat group.View on attack.mitre.org

About this group

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.

North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.

Techniques used93

Procedure examples93

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

Lazarus Group malware also uses a unique form of communication encryption known as FakeTLS that mimics TLS but uses a different encryption method, potentially evading SSL traffic inspection/decryption.

T1005
Data from Local System

Lazarus Group has collected data and files from compromised networks.

T1008
Fallback Channels

Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again.

T1010
Application Window Discovery

Lazarus Group malware IndiaIndia obtains and sends to its C2 server the title of the window for each running process. The KilaAlfa keylogger also reports the title of the window in the foreground.

T1012
Query Registry

Lazarus Group malware IndiaIndia checks Registry keys within HKCU and HKLM to determine if certain applications are present, including SecureCRT, Terminal Services, RealVNC, TightVNC, UltraVNC, Radmin, mRemote, TeamViewer, FileZilla, pcAnyware, and Remote Desktop. Another Lazarus Group malware sample checks for the presence of the following Registry key:HKEY_CURRENT_USER\Software\Bitcoin\Bitcoin-Qt.

T1016
System Network Configuration Discovery

Lazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card’s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available.

T1021.001
Remote Desktop Protocol

Lazarus Group malware SierraCharlie uses RDP for propagation.

T1021.002
SMB/Windows Admin Shares

Lazarus Group malware SierraAlfa accesses the ADMIN$ share via SMB to conduct lateral movement.

T1021.004
SSH

Lazarus Group used SSH and the PuTTy PSCP utility to gain access to a restricted segment of a compromised network.

T1027.007
Dynamic API Resolution

Lazarus Group has used a custom hashing method to resolve APIs used in shellcode.

T1027.009
Embedded Payloads

Lazarus Group has distributed malicious payloads embedded in PNG files.

T1027.013
Encrypted/Encoded File

Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names.

T1033
System Owner/User Discovery

Various Lazarus Group malware enumerates logged-on users.

T1036.003
Rename Legitimate Utilities

Lazarus Group has renamed system utilities such as wscript.exe and mshta.exe.

T1036.004
Masquerade Task or Service

Lazarus Group has used a scheduled task named `SRCheck` to mask the execution of a malicious .dll.

View all 93 procedure examples

Software26

Show 2 more

Campaigns1

References6

  1. JPCert Blog Laz Subgroups 2025 Open source
    佐々木勇人 Hayato Sasaki. (2025, March 25). Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup. Retrieved August 25, 2025.
  2. Mandiant DPRK Groups 2023 Open source
    Michael Barnhart, Austin Larsen, Jeff Johnson, Taylor Long, Michelle Cantos, Adrian Hernandez. (2023, October 10). Assessed Cyber Structure and Alignments of North Korea in 2023. Retrieved August 25, 2025.
  3. Mandiant DPRK Laz Org Breakdown 2022 Open source
    Michael Barnhart, Michelle Cantos, Jeffery Johnson, Elias fox, Gary Freas, Dan Scott. (2022, March 23). Not So Lazarus: Mapping DPRK Cyber Threat Groups to Government Organizations. Retrieved September 9, 2025.
  4. Novetta Blockbuster Open source
    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.
  5. Treasury North Korean Cyber Groups September 2019 Open source
    US Treasury . (2019, September 13). Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups. Retrieved September 29, 2021.
  6. US-CERT HIDDEN COBRA June 2017 Open source
    US-CERT. (2017, June 13). Alert (TA17-164A) HIDDEN COBRA – North Korea’s DDoS Botnet Infrastructure. Retrieved July 13, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.