Skip to main content
QUIETLYTIC
Threat Actor

Lazarus Group

North Korean state-sponsored threat group attributed by MITRE ATT&CK to the Reconnaissance General Bureau (RGB), active since at least 2009 and linked to the 2014 Sony Pictures wiper attack.

Threat Level
CRITICAL
Attribution
Reconnaissance General Bureau (RGB), North Korea — per MITRE ATT&CK's group profile
Also Known As
Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet
Targets
Entertainment and media (Sony Pictures Entertainment, 2014), Financial and cryptocurrency organizations, Government and critical infrastructure

Overview

Lazarus Group (MITRE ATT&CK ID G0032) is a North Korean state-sponsored cyber threat group MITRE ATT&CK attributes to the Reconnaissance General Bureau (RGB), active since at least 2009. Per MITRE’s group profile, Lazarus Group is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by security firm Novetta as part of “Operation Blockbuster.” MITRE’s description also links malware attributed to the group to other reported campaigns including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.

Attribution caveat

MITRE ATT&CK’s own documentation is explicit that North Korea’s cyber operations show a consistent pattern of adaptation, with units forming and reorganizing as national priorities shift, frequently sharing personnel, infrastructure, malware, and tradecraft — making it difficult to attribute specific operations with high confidence. Per MITRE, public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns, rather than one cleanly bounded organization.

Known tools and malware (per MITRE ATT&CK relationship data)

Our ingested data links Lazarus Group to malware including WannaCry, AppleJeus, BLINDINGCAN, ThreatNeedle, Dtrack, HOPLIGHT, FALLCHILL, KEYMARBLE, HotCroissant, MagicRAT, and TAINTEDSCRIBE, among a broad toolset MITRE documents against the group.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques linked to Lazarus Group in our data include Account Manipulation (T1098), Archive Collected Data (T1560) and its Archive via Custom Method (T1560.003) and Archive via Library (T1560.002) variants, Bidirectional Communication (T1102.002), and Bootkit (T1542.003).

Per MITRE ATT&CK’s relationship data, Lazarus Group is linked to Operation Dream Job, a cyber-espionage operation targeting defense, aerospace, and government sectors.

What we don’t have

MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2009” per MITRE’s description text. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and given MITRE’s own note on DPRK cluster-attribution difficulty, we don’t treat “Lazarus Group” attributions as a precise organizational boundary.

Frequently Asked Questions

What is Lazarus Group? A North Korean state-sponsored threat group, per MITRE ATT&CK, attributed to the Reconnaissance General Bureau and active since at least 2009, linked to the 2014 Sony Pictures Entertainment wiper attack.

Is “Lazarus Group” one specific team? Not precisely — MITRE ATT&CK’s own documentation notes it’s often used as an umbrella term for multiple North Korean cyber operators whose personnel, infrastructure, and tradecraft overlap and shift over time.

What malware is Lazarus Group linked to? Per MITRE ATT&CK’s relationship data: WannaCry, AppleJeus, BLINDINGCAN, ThreatNeedle, Dtrack, HOPLIGHT, and MagicRAT, among others.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0032, aggregated August 28, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools