Lazarus Group (APT38): North Korea's Most Prolific Cyber Threat Actor Targets Banks, Crypto, and Critical Infrastructure

A comprehensive threat profile published by Brandefense documents over a decade of operations by the Lazarus Group — North Korea's most sophisticated and destructive state-sponsored threat actor — cataloguing campaigns ranging from destructive DDoS and ransomware attacks to billion-dollar financial heists and pharmaceutical espionage, with the FBI formally designating the group a North Korean state-sponsored hacking organization.

Origins and Aliases

Active since at least 2009, Lazarus Group operates under an extensive web of aliases including APT38, HIDDEN COBRA, Zinc (Microsoft), Guardians of Peace, Labyrinth Chollima, Bureau 121, and Unit 121. The group is known to encompass subgroups — most notably Andariel and Bluenoroff — each with specialized mandates covering financial crime and destructive operations respectively. Malware attributed to the group has been detected across 18 countries spanning North America, South America, Europe, the Middle East, and Asia-Pacific.

A Decade of High-Impact Operations

Lazarus has pursued four primary objectives across its operational history: money extortion, information theft, sabotage, and espionage. Key milestones include:

Toolset and Malware Arsenal

Lazarus maintains a layered toolkit combining off-the-shelf utilities with purpose-built implants. For lateral movement, the group leverages AdFind, SMBMap, Mimikatz, and Responder. Credential harvesting employs XenArmor Email Password Recovery Pro and XenArmor Browser Password Recovery Pro, while network reconnaissance uses tcpdump and TightVNC Viewer. Custom malware attributed to the group includes AppleJeus, BADCALL, Bankshot, BLINDINGCAN, Dtrack, KEYMARBLE, ThreatNeedle, Torisma, and WannaCry — a breadth that reflects both the group's longevity and the operational specialization within its subgroups.

Persistent Targeting of Financial and Critical Infrastructure

Lazarus's sector targeting spans banking, defense, software, pharmaceuticals, cryptocurrency platforms, manufacturing, and electrical infrastructure — a combination that reflects both revenue-generation and strategic intelligence collection mandates. Spear-phishing and exploitation of known vulnerabilities remain the dominant initial access vectors across the group's campaigns, underscoring that even one of the world's most capable threat actors continues to rely on social engineering as its most reliable entry point.

Detection coverage

Read the full analysis on IntelFusions