Skip to content

APT group profile

Lazarus Group

North Korean state-sponsored group attributed to the Reconnaissance General Bureau (RGB), active since at least 2009, that combines espionage, sabotage and financial theft against banking, crypto assets and defense, with documented cases in Latin America.

MITRE G0032 EspionageFinancialSabotage / destructive LATAM Updated

Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.

MITRE ATT&CK techniques

Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.

Reconnaissance

  • T1591.004 Gather Victim Org Information: Identify Roles

Resource Development

  • T1585.001 Establish Accounts: Social Media Accounts
  • T1587.001 Develop Capabilities: Malware

Initial Access

Execution

  • T1047 Windows Management Instrumentation
  • T1053.005 Scheduled Task/Job: Scheduled Task
  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1204.002 User Execution: Malicious File
  • T1574.001 Hijack Execution Flow: DLL

Persistence

  • T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Stealth

  • T1070.004 Indicator Removal: File Deletion
  • T1218.011 System Binary Proxy Execution: Rundll32

Defense Impairment

  • T1553.002 Subvert Trust Controls: Code Signing

Credential Access

Lateral Movement

  • T1021.002 Remote Services: SMB/Windows Admin Shares

Command and Control

  • T1071.001 Application Layer Protocol: Web Protocols
  • T1102.002 Web Service: Bidirectional Communication

Exfiltration

  • T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Impact

  • T1485 Data Destruction
  • T1529 System Shutdown/Reboot

Malware and tools

References

Public sources this profile is based on.

  1. [1] Lazarus Group, Group G0032 · MITRE ATT&CK
  2. [2] APT38, Group G0082 · MITRE ATT&CK
  3. [3] Andariel, Group G0138 · MITRE ATT&CK
  4. [4] United States v. Jon Chang Hyok, Kim Il y Park Jin Hyok (acusación formal) · U.S. Department of Justice, Dec 2020
  5. [5] Lazarus Under The Hood · Kaspersky, Apr 2017
  6. [6] Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America · Trend Micro, Nov 2018
  7. [7] Researchers Link Chilean Interbank Attack to North Korea · SecurityWeek (investigación de Flashpoint), Jan 2019
  8. [8] Operation In(ter)ception: Aerospace and military companies in the crosshairs of cyberspies · ESET, Jun 2020
  9. [9] TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies (AA22-108A) · CISA, Apr 2022
  10. [10] North Korea Responsible for $1.5 Billion Bybit Hack · FBI, Feb 2025
  11. [11] Gotta fly: Lazarus targets the UAV sector · ESET, Oct 2025
  12. [12] Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack · Check Point Research, Aug 2026

Profile last updated:

Concerned about this group?

The Ventura Systems MDR service monitors the techniques of this and other actors 24/7, with ATT&CK-based threat hunting.