Lazarus Group

APT / StateG0032
Origin🇰🇵 Coreia do Norte
Techniques (MITRE ATT&CK)93
SourceMITRE ATT&CK
State sponsor: Korea (Democratic People's Republic of)Attribution confidence: 50%Target categories: Government, Private sector
Targeted regions: South Korea · Bangladesh Bank · Sony Pictures Entertainment · United States · Thailand · France · China · Hong Kong · United Kingdom · Guatemala +9
Also known as:APT 38APT-C-26APT38ATK117ATK3AndarielApplewormBeagleBoyzBlack ArtemisBluenoroffBureau 121COPERNICIUMCOVELLITECitrine SleetDEV-0139DEV-1222Dark SeoulDiamond SleetG0032G0082Group 77Guardians of PeaceHIDDEN COBRAHastati GroupHidden CobraLabyrinth ChollimaMoonstone SleetNICKEL ACADEMYNICKEL GLADSTONENewRomanic Cyber Army TeamNickel AcademyOperation AppleJeusOperation DarkSeoulOperation GhostSecretOperation TroySapphire SleetStardust ChollimaSubgroup: BluenoroffTA404Unit 121Whois Hacking TeamZINCZinc

Vexday analysis

Lazarus Group é um grupo de ameaça persistente avançada (APT) patrocinado pelo Estado norte-coreano e atribuído ao Reconnaissance General Bureau (RGB), ativo pelo menos desde 2009. O grupo, rastreado pela MITRE ATT&CK sob o identificador G0032 e também conhecido pelos aliases Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY e Diamond Sleet, é apontado como responsável pelo ataque destrutivo de novembro de 2014 contra a Sony Pictures Entertainment, identificado pela Novetta como parte da Operação Blockbuster. Malwares associados ao grupo foram correlacionados a outras campanhas documentadas, incluindo Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul e Ten Days of Rain. Ao todo, 93 técnicas MITRE ATT&CK foram documentadas em suas operações, além de uma CVE atribuída ao grupo.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity81
Impact: High
T1189T1047T1098T1110.003T1005T1041ENTRYInitial accessDrive-byCompromiseEXECExecutionWindows ManagementInstrumentationPERSPersistenceAccountManipulationCREDCredential accessPassword SprayingCOLLCollectionData from LocalSystemEXFILExfiltrationExfiltration OverC2 ChannelIMPACTImpactData Destruction

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 93

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 1

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 16

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

sha256_hash99675dee76e7e6ef051bca3da95870d518b53c757d7cdbed045b1137911884b5WannaCrymalwarebazaar
sha256_hashf2257d01dde12339f8bc370eabc74fa487e116b47f61f2094472885b9e4cb631WannaCrymalwarebazaar
sha256_hashed597d3121d614edf3aa79636783ce962732c579f2786c83c5585c43b6847a90WannaCrymalwarebazaar
sha256_hash1e78e60de13290234f642709674835e7b400102d7d22367266fd38329782e58eWannaCrymalwarebazaar
sha256_hash960a43b385f4370b19590ea7c9250acabb0ecb0df4fb8fb28d970bde643dbbd6WannaCrymalwarebazaar
sha256_hash05be5a8131993a5034bc4a57963f0c8860aeb3188dd906ed78d95439d15d813eWannaCrymalwarebazaar
sha256_hash2521192853e4857386d89f555851adfdebde3a939199f939f93068058718e72eWannaCrymalwarebazaar
sha256_hash9767724a6dd381d9401bcd0ea8c082d3b009c59ab949d6e25970f1de848354afWannaCrymalwarebazaar
sha256_hash32c9bf96fb8c0d6ad0d3a3d2707a8a9ae0b95ccefaa26ad0e33b518d9fd0a608WannaCrymalwarebazaar
sha256_hash545bf734fc18a564c334aaf0894295c1e7d123bb4ff274f3ed66f2a16f3bbbabWannaCrymalwarebazaar
sha256_hash71fcbb434b354f3d49979deb66e458086f266f36c6a161e46cd924445bd22c65WannaCrymalwarebazaar
sha256_hash2c2883d25e71c2859b16ac28757e3754f33767931aa98d5a9e705c374818e8f5WannaCrymalwarebazaar
sha256_hash1ab810f65b846b0d1aef311bda3d0e96dcc806dd7bdfc7eb414a68d53786a6adWannaCrymalwarebazaar
sha256_hashe4846ec6171f65e96c2909ad93359451551e3ac95aa89ab349d5ab773cbaa0d6WannaCrymalwarebazaar
sha256_hashbecb96feeca38c60ffe947656e5a7eaadca38be472531ef69efb1e5fe3c02205WannaCrymalwarebazaar
sha256_hash9b90e3a119436b64ead0edfde7a8be2221fce6073f369c4065803320f9bfd655WannaCrymalwarebazaar

Lazarus Group uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →