Lazarus Group
Lazarus Group
Lazarus Group is the name commonly used in public reporting for a state-linked cyber threat actor widely attributed to North Korea (DPRK). It is associated with a long-running set of cyber-espionage, sabotage, and financially motivated hacking campaigns that have targeted governments, military organizations, critical infrastructure, media, banks, and cryptocurrency services worldwide.
Attribution and naming
The label “Lazarus Group” is used by cybersecurity companies and government agencies to describe what is believed to be a cluster of related teams and operations, rather than a single, clearly bounded organization. Public attributions frequently connect Lazarus activity to North Korean state interests, including intelligence collection and revenue generation to support the regime under international sanctions.
Typical objectives
Lazarus Group has been described as pursuing multiple goals, often overlapping:
- Cyber-espionage: theft of sensitive government, defense, and industrial information.
- Disruptive and destructive attacks: operations intended to degrade or destroy systems, or to send political messages.
- Financial theft: intrusions into banks and payment systems, and theft from cryptocurrency exchanges and DeFi platforms, often followed by laundering through complex networks of accounts and services.
Common tactics (high-level)
Public reporting commonly associates Lazarus operations with:
- Spearphishing and social engineering to gain initial access
- Use of malware families and backdoors that are retooled across campaigns
- Supply-chain compromise and trojanized software in some incidents
- Credential theft, lateral movement, and data exfiltration within victim networks
- Targeting of cryptocurrency wallets, bridges, and exchange infrastructure, followed by laundering steps
Relationship to other names
Within threat-intelligence reporting, Lazarus is often discussed alongside or as an umbrella for related activity groups (names vary by vendor), reflecting differences in how organizations cluster incidents and tools. As a result, the exact boundaries of “Lazarus Group” can differ across sources.
Significance
Lazarus Group is widely regarded as one of the most consequential nation-state–linked cyber actors due to its global reach, operational persistence, and the combination of strategic espionage and large-scale financial theft.
If you want, I can also provide a short timeline of major publicly reported incidents associated with Lazarus, formatted as a table.
Related Bitcoin addresses:
Total 14 addresses.