North KoreaFormally attributedActiveMITRE G0032

Lazarus Group

Coverage omission — Eastern

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
18.9
High signal strength
Mentions28
Sources5
High conf.17
Last seenMay 2026
First observed
2017-05-31
Last active
Active
Origin
North Korea — attributed by US, UK, and South Korean governments to RGB (Reconnaissance General Bureau)
Aliases
13
Techniques
93
Campaigns
11
North Korea — attributed by US, UK, and South Korean governments to RGB (Reconnaissance General Bureau)consensus confidence
TargetsFinancialCryptocurrencyDefenceMedia
RegionsUsKrJpEuGlobal

Attribution signals

28 mentions · 5 sources
#1confirmedhigh
HUMINT
wiz-research
May 2026

"the FBI, CISA, and U.S. Treasury confirmed that the DPRK-backed entities behind TraderTraitor are tracked as Lazarus Group, APT38, BlueNoroff, and Stardust Chollima"

Campaign: TraderTraitor
#2attributed tohigh
InfrastructureVictimology
wechat-qax-ti
May 2026

"attributed to Lazarus Group"

#3attributedhigh
HUMINT
recorded-future
May 2026

"The FBI attributed approximately $1.5 billion in stolen virtual assets to TraderTraitor in February 2025."

#4attributed tohigh
Malware
eset
May 2026

"it was seen in the wild, and since then in multiple attacks attributed to Lazarus' Operation DreamJob campaigns"

Campaign: Operation DreamJob
#5we track underhigh
TTP matchMalware
eset
May 2026

"a campaign that we track under the umbrella of North Korea-aligned Lazarus"

Campaign: Operation DreamJob
#6conducted byhigh
TTP matchMalwareVictimology
eset
May 2026

"ESET research analyzes a recent instance of the Operation DreamJob cyberespionage campaign conducted by Lazarus, a North Korea-aligned APT group"

Campaign: Operation DreamJob
#7trackedhigh
TTP match
eset
May 2026

"We also tracked the continuing evolution of Lazarus campaigns, including Operation DreamJob and Operation DangerousPassword."

Campaign: Operation DreamJob, Operation DangerousPassword
#8has posedhigh
TTP matchMalware
eset
May 2026

"North Korea's Lazarus Group has posed as recruiters on LinkedIn to install malware on the machines of individuals working in an aerospace company, as discovered by ESET Research."

#9identifiedhigh
MalwareTTP matchVictimology
wechat-qax-ti
May 2026

"Lazarus organization is launching ClickFix attacks against high-value environments using macOS systems"

#10assessed as high-confidencehigh
GeopoliticalTTP matchVictimology
wechat-qax-ti
May 2026

"Expel discovers and continuously tracks HexagonalRodent (alias Famous Chollima subset), assessed as high-confidence DPRK state-sponsored APT sub-group."

#11we attribute with a high level of confidencehigh
TTP matchMalwareVictimology
eset
May 2026

"In summary, we attribute this activity with a high level of confidence to Lazarus, particularly to its campaigns related to Operation DreamJob"

Campaign: Operation DreamJob
#12continuedhigh
TTP match
eset
May 2026

"Lazarus and DeceptiveDevelopment continued to invest in long-term relationship building with high-value targets"

Hedge terms observed

assessed as high-confidenceassociated withattributedattributed tocommon inconducted byconfirmedconsistent withcontinuedhas been tied tohas posedidentifiedisled toNorth Korea-alignedoverlaps withstoletrackedunspecifiedusedwe attribute with a high level of confidencewe track under