Threat ActorHuman reviewed 2026-08-26 · MITRE ATT&CK · CISA

Lazarus Group

North Korea-linked threat group (Lazarus / Hidden Cobra) active since at least 2009, responsible for the 2014 Sony breach, WannaCry and a decade of cryptocurrency and banking heists.

QUICK ANSWER

Lazarus Group is North Korea's cyber threat group behind the 2014 Sony breach and the 2017 WannaCry outbreak, now best known for large-scale cryptocurrency-exchange heists to fund state operations.

Definition

State-sponsored hacking group attributed to North Korea (Bureau 121); conducts destructive attacks, long-running espionage, supply-chain implants (3CX) and financially motivated cryptocurrency theft.

Why It Matters / Profile

  • Sponsorship: Democratic People's Republic of Korea (assessed)
  • Active since: 2009
  • Aliases: Hidden Cobra, ZINC, APT38, Diamond Sleet

Current Status

  • Review status: published
  • Last updated: 2026-08-26
  • Evidence: 2 source(s) · 4 technique(s)
  • Confidence: 90%

ATT&CK Techniques

Targets

  • Cryptocurrency exchanges
  • Banks
  • Gaming
  • Financial infrastructure

Timeline

  1. 2009-01-01 — Attributed origins (approx.)
  2. 2014-11-01 — Sony Pictures destructive attack
  3. 2023-01-01 — 3CX software supply-chain attack (approx.)

Sources

Start Investigation

Move from reading to investigating Lazarus Group. The workspace is a structured analysis surface — not a chat — organised as:

  1. Question — what do you need to know about Lazarus Group?
  2. Evidence — assertions mapped to verifiable references.
  3. Timeline — events in chronological order.
  4. Related Entities — CVE, threat actor, campaign, malware links.
  5. Sources — NVD, CISA KEV, MITRE ATT&CK, vendor advisories.
  6. Notes — your own observations and working hypotheses.

AI assistance is limited to summarising, explaining, and suggesting related evidence. AI never completes your investigation, modifies entity relationships, or generates facts — all published analysis stays human-reviewed.

Recommended Tools

  • IOC LookupSearch OpenTrojan intelligence for indicators attributed to this actor.Look up IOC

Every tool runs passively or locally — inputs are never stored and no target is scanned. Start an investigation on this entity →