- Home
- APT groups
- Lazarus Group
APT group profile
Lazarus Group
North Korean state-sponsored group attributed to the Reconnaissance General Bureau (RGB), active since at least 2009, that combines espionage, sabotage and financial theft against banking, crypto assets and defense, with documented cases in Latin America.
Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.
Overview
Lazarus Group is a North Korean state-sponsored actor that MITRE ATT&CK attributes to the Reconnaissance General Bureau (RGB), with activity since at least 2009. It is associated with the destructive attack on Sony Pictures (2014), the WannaCry ransomware campaign (2017) and a long series of thefts from banks and crypto-asset companies. The 2020 DOJ indictment describes the defendants as members of RGB units “known as Lazarus Group and APT38” and charges them with attempted theft or extortion of more than $1.3 billion.
It is important to be precise about the scope of the name. MITRE cautions that “Lazarus” is often used as an umbrella term for several North Korean operators that share personnel, infrastructure and malware, and it maintains separate entries for APT38 (also called BlueNoroff or Sapphire Sleet), dedicated to financial operations against banks, SWIFT, ATMs and exchanges, and for Andariel (Onyx Sleet), focused on South Korea. This profile notes which subgroup each source assigns a case to, when it does so.
For Latin America, Lazarus and its financial subgroup are the North Korean actors with the most extensive public track record in the region. They have attacked banking infrastructure in Mexico and Chile, regulator and bank websites used as watering holes, online casinos in Central America and, in 2026, defense companies in Brazil.
Notable campaigns
- 2014, Sony Pictures: destructive attack with data theft and leaks, charged to the RGB in the DOJ indictment.
- 2016–2017, watering holes against the financial sector: according to Kaspersky, BlueNoroff compromised websites visited by its targets in nine countries, including Mexico, Uruguay and Peru.
- 2017, WannaCry and casino extortion: the DOJ attributes to the conspiracy the authorship of WannaCry and the extortion of two online casinos based in Central America.
- 2018 (January), Bancomext, Mexico: fraudulent transfers of about $110 million and malware on more than 400 machines, according to the DOJ. MITRE assigns this case to APT38, along with the Banco de Chile case.
- 2018 (September), Latin American financial institutions: Trend Micro documented the installation of modular backdoors and attributed the activity to the BlueNoroff subgroup.
- 2018 (December), Redbanc, Chile: an IT professional was approached with a fake job offer and interviewed in Spanish over Skype. He then ran a “form” that downloaded PowerRatankba. Flashpoint, via SecurityWeek, linked that tool to Lazarus.
- 2019–2020, Operation In(ter)ception / Dream Job: fake job offers via LinkedIn against aerospace and military companies in Europe and the Middle East. ESET noted possible links to Lazarus, without conclusive attribution.
- 2022, TraderTraitor: CISA warned of trojanized crypto-asset applications distributed with recruitment lures. The activity is tracked as Lazarus, APT38 or BlueNoroff.
- 2025 (February), Bybit: the FBI attributed to North Korea (TraderTraitor) the theft of about $1.5 billion in virtual assets.
- 2025, drone sector in Europe: ESET reported a new Dream Job wave against defense manufacturers with UAV projects, using ScoringMathTea.
- 2026, Dream Job with a Windows zero-day: according to Check Point Research, CVE-2026-68820 (AFD.sys) was exploited against defense and aerospace companies in Brazil, France, Germany and India. Check Point has been tracking this wave of the campaign since early 2026 (published in August 2026).
Key TTPs
Reconnaissance and resource development. The group studies LinkedIn to identify specific roles (T1591.004), creates fake recruiter profiles (T1585.001) and develops its own malware (T1587.001).
Initial access and execution. Its hallmark is job-themed social engineering: contact via social media or messaging (T1566.003), followed by malicious documents or links (T1566.001, T1566.002) that the victim opens on their own (T1204.002). It then uses PowerShell (T1059.001) and WMI (T1047). The DOJ indictment also describes watering holes and the Brambul worm, which spread over SMB using weak passwords (T1110.003).
Persistence and evasion. It uses Run keys (T1547.001), scheduled tasks (T1053.005), DLL loading (T1574.001), execution via rundll32 (T1218.011), signed binaries (T1553.002) and artifact deletion (T1070.004).
Lateral movement, C2 and exfiltration. It moves through SMB administrative shares (T1021.002). For C2 it uses HTTP/HTTPS (T1071.001) and legitimate services such as GitHub (T1102.002), and it exfiltrates to cloud storage (T1567.002).
Impact. In destructive operations or to cover up thefts, it wipes data (T1485) and forces reboots after damaging the MBR (T1529).
Detection and mitigation
- Job-themed social engineering: train IT, DevOps, treasury and payments teams on fake job offers and technical interviews that require running code, PDFs or “tests” (M1017). Prohibit running files received via LinkedIn, WhatsApp, Telegram or Skype on corporate machines.
- Execution control: apply allowlists and ASR rules against child processes of Office and PDF readers (M1038, M1040). Monitor
rundll32,regsvr32,mshtaandwmiclaunched from user profiles or%TEMP%. - Minimum telemetry: log Sysmon (events 1, 3, 7, 11 and 13), Windows events 4688/4698, PowerShell Script Block Logging (4104) and EDR telemetry. Correlate recent downloads with persistence in
Runor in scheduled tasks. - SWIFT, ATM and payment switch environments: segment them and require MFA on administrative jump hosts (M1030, M1032), in line with the SWIFT CSP framework. Monitor off-hours logins and reconcile sent messages against independent records.
- Crypto assets: multisignature custody and out-of-band approval for withdrawals. Restrict the workstations that sign transactions and review FBI and CISA alerts on TraderTraitor.
- Priority patching: fix actively exploited kernel privilege escalation vulnerabilities, such as CVE-2026-68820 (M1051), and enable the vulnerable driver blocklist.
- Hunting: look for C2 traffic to GitHub, Dropbox, OneDrive or Graph API from unusual processes and binaries signed with uncommon certificates. Also review timestomping on newly created executables and mass SMB connections to
ADMIN$. - Resilience against destruction: maintain offline, immutable backups (M1053) and test recovery of domain controllers and core banking systems.
MITRE ATT&CK techniques
Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.
Reconnaissance
- T1591.004 Gather Victim Org Information: Identify Roles
Resource Development
Initial Access
Execution
Persistence
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Stealth
Defense Impairment
- T1553.002 Subvert Trust Controls: Code Signing
Credential Access
- T1110.003 Brute Force: Password Spraying
Lateral Movement
- T1021.002 Remote Services: SMB/Windows Admin Shares
Command and Control
Exfiltration
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Malware and tools
Malware
- WannaCry S0366
- RawDisk S0364
- RATANKBA S0241
- AppleJeus S0584
- BLINDINGCAN S0520
- ThreatNeedle S0665
- DRATzarus S0694
- Torisma S0678
- Dtrack S0567
- HOPLIGHT S0376
- FALLCHILL S0181
- MagicRAT S1182
- PowerRatankba
- ScoringMathTea / ForestTiger
- Troy
References
Public sources this profile is based on.
- [1] Lazarus Group, Group G0032 · MITRE ATT&CK
- [2] APT38, Group G0082 · MITRE ATT&CK
- [3] Andariel, Group G0138 · MITRE ATT&CK
- [4] United States v. Jon Chang Hyok, Kim Il y Park Jin Hyok (acusación formal) · U.S. Department of Justice, Dec 2020
- [5] Lazarus Under The Hood · Kaspersky, Apr 2017
- [6] Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America · Trend Micro, Nov 2018
- [7] Researchers Link Chilean Interbank Attack to North Korea · SecurityWeek (investigación de Flashpoint), Jan 2019
- [8] Operation In(ter)ception: Aerospace and military companies in the crosshairs of cyberspies · ESET, Jun 2020
- [9] TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies (AA22-108A) · CISA, Apr 2022
- [10] North Korea Responsible for $1.5 Billion Bybit Hack · FBI, Feb 2025
- [11] Gotta fly: Lazarus targets the UAV sector · ESET, Oct 2025
- [12] Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack · Check Point Research, Aug 2026
Profile last updated: