A comprehensive threat profile published by Brandefense documents over a decade of operations by the Lazarus Group — North Korea's most sophisticated and destructive state-sponsored threat actor — cataloguing campaigns ranging from destructive DDoS and ransomware attacks to billion-dollar financial heists and pharmaceutical espionage, with the FBI formally designating the group a North Korean state-sponsored hacking organization.
Origins and Aliases
Active since at least 2009, Lazarus Group operates under an extensive web of aliases including APT38, HIDDEN COBRA, Zinc (Microsoft), Guardians of Peace, Labyrinth Chollima, Bureau 121, and Unit 121. The group is known to encompass subgroups — most notably Andariel and Bluenoroff — each with specialized mandates covering financial crime and destructive operations respectively. Malware attributed to the group has been detected across 18 countries spanning North America, South America, Europe, the Middle East, and Asia-Pacific.
A Decade of High-Impact Operations
Lazarus has pursued four primary objectives across its operational history: money extortion, information theft, sabotage, and espionage. Key milestones include:
- 2009 — Operation Troy: Large-scale DDoS attacks against U.S. and South Korean government websites using Mydoom and Dozer malware, striking approximately three dozen targets and writing "Memory of Independence Day" to infected systems' master boot records.
- 2014 — Sony Pictures Breach: Operating under the "Guardians of Peace" persona, Lazarus exfiltrated unreleased films, executive emails, and personal records of roughly 4,000 employees — reportedly after maintaining covert access for over a year prior to the public breach on November 24.
- 2016 — Bangladesh Bank Heist: Using fraudulent SWIFT instructions, the group attempted to steal nearly $1 billion from the Federal Reserve Bank of New York account of Bangladesh Bank. Five of thirty-five instructions succeeded, transferring $101 million — $81 million to the Philippines and $20 million to Sri Lanka — before a misspelled instruction in a remaining transaction triggered a block on the other $850 million.
- 2017 — WannaCry Ransomware: The self-propagating cryptoworm infected an estimated 200,000 computers across 150 countries in under eight hours, hitting organizations ranging from the UK's NHS to Boeing and Chinese universities. The U.S. Department of Justice and UK authorities formally attributed WannaCry to Lazarus.
- 2020 — Pharmaceutical Targeting: During the COVID-19 pandemic, Lazarus members posed as health officials in spear-phishing campaigns against vaccine researchers, with AstraZeneca confirmed as a targeted organization.
- 2022 — Cryptocurrency Theft: Lazarus deployed trojanized Windows and macOS cryptocurrency applications to steal private keys, linked by authorities to the $625 million Ronin Network theft. The group has stolen an estimated $1.7 billion in cryptocurrency over recent years, including through nearly 200 malicious mining apps discovered on the Google Play Store.
Toolset and Malware Arsenal
Lazarus maintains a layered toolkit combining off-the-shelf utilities with purpose-built implants. For lateral movement, the group leverages AdFind, SMBMap, Mimikatz, and Responder. Credential harvesting employs XenArmor Email Password Recovery Pro and XenArmor Browser Password Recovery Pro, while network reconnaissance uses tcpdump and TightVNC Viewer. Custom malware attributed to the group includes AppleJeus, BADCALL, Bankshot, BLINDINGCAN, Dtrack, KEYMARBLE, ThreatNeedle, Torisma, and WannaCry — a breadth that reflects both the group's longevity and the operational specialization within its subgroups.
Persistent Targeting of Financial and Critical Infrastructure
Lazarus's sector targeting spans banking, defense, software, pharmaceuticals, cryptocurrency platforms, manufacturing, and electrical infrastructure — a combination that reflects both revenue-generation and strategic intelligence collection mandates. Spear-phishing and exploitation of known vulnerabilities remain the dominant initial access vectors across the group's campaigns, underscoring that even one of the world's most capable threat actors continues to rely on social engineering as its most reliable entry point.