EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/espionage-operation/lazarus-group-attacks
382/430

File EL-0049CriticalOngoingEspionage Operation / Nation-State Cyber Espionage

Lazarus Group Attacks

Also filed as DPRK Cyber Operations · North Korea Cyber Threat Group

The Lazarus Group is a sophisticated, state-sponsored cyber threat actor attributed to North Korea. They are known for conducting highly targeted espionage operations and large-scale financial theft. Their activities span diverse sectors, including banking, media, and critical infrastructure, making them a persistent global threat.

  • #north-korea
  • #apt
  • #cyber-espionage
  • #financial-theft
  • #lazarus-group
  • #dprk
Notoriety9/10
Event
1 Jan 2009
Disclosed
1 Jan 2013
Target
Global Financial and Tech Targets
Actor
Lazarus Group
Scale
Varies widely; from small intelligence packets to large financial transaction records.
Status
Ongoing

01Summary

The Lazarus Group has evolved from early cyber espionage activities into a highly profitable criminal enterprise for the DPRK regime. Initially focused on stealing intellectual property and political secrets, their operations expanded significantly after 2014 to include large-scale cryptocurrency theft and bank heists. They utilize sophisticated malware, including custom loaders and banking trojans, to maintain persistence and exfiltrate data. The group's methods often involve spear-phishing campaigns targeting high-value individuals and exploiting zero-day vulnerabilities in supply chains. Their financial motives are paramount, with documented attacks on SWIFT infrastructure and major cryptocurrency exchanges, demonstrating a blend of intelligence and criminal capabilities.

02Background

The group's origins are rooted in the DPRK's need to generate foreign currency to bypass international sanctions. Early reports traced their activities to the theft of sensitive data from South Korean and Western targets. Over time, their operational scope broadened from simple espionage to complex, multi-stage financial attacks, marking a shift toward cyber-enabled criminal activity.

03Key revelations

  1. 01The group's shift from pure espionage to large-scale, profit-driven cybercrime.
  2. 02Successful attacks on major cryptocurrency exchanges and SWIFT-linked financial institutions.
  3. 03The use of sophisticated, multi-stage malware designed to bypass modern security defenses.

04Technical analysis

Lazarus Group employs a multi-stage attack chain, typically beginning with spear-phishing emails containing malicious attachments or links. Initial access is often gained through compromised third-party vendors or exploiting known vulnerabilities. Once inside, they utilize custom malware families (e.g., banking trojans, loaders) to establish persistence, move laterally across the network, and finally exfiltrate data or initiate fund transfers. Their malware is often highly customized to evade signature-based detection.

Attack vector
Spear-phishing, Supply Chain Compromise, Exploitation of Vulnerabilities
Attack method
Espionage and Financial Theft
Initial access
Phishing/Spear-Phishing
Lateral movement
Pass-the-Hash, Exploiting internal network trust
Persistence
Backdoors, Scheduled Tasks, Registry Modification
Exfiltration
Encrypted channels, Compromised VPNs
Tool / malware
Malicious loaders, Banking Trojans, Custom Malware
Malware family
Trojans, Stealers, Backdoors
Malware type
Spyware, Stealer, Backdoor

Vulnerabilities exploited

  • CVE-2017-1188
  • Zero-day exploits (general)

MITRE ATT&CK techniques

  • T1566.001
  • T1071.001
  • T1190

05Threat actor

The Lazarus Group is considered one of the most financially motivated and technically advanced state-sponsored threat actors. They are characterized by their ability to pivot seamlessly between traditional espionage (stealing IP) and modern cybercrime (stealing crypto), making them exceptionally difficult to attribute and defend against.

Aliases

  • Hidden Cobra
  • APT38
  • DPRK Cyber Unit

APT designations

  • APT38
  • Hidden Cobra

MITRE groups

  • T1071.001
  • T1566.001
  • T1190

Attribution sources

  • United States Department of Treasury
  • Mandiant (Google)
  • FireEye
  • Reuters

06Victims and impact

Additional victims

  • Major Banks
  • Media Outlets
  • Government Agencies

Countries affected

  • United States
  • South Korea
  • United Kingdom
  • Global

07Data exposed

Data types

  • Credentials
  • Financial Records
  • Intellectual Property
  • Personal Identifiable Information (PII)
  • Classified Documents

Notable documents

  • SWIFT Transaction Logs (hypothetical)
  • Compromised Corporate Credentials

08Financial damage

Damage is cumulative and estimated in the billions of USD across multiple, unquantified incidents.

09Timeline

  1. 2013-01-01Initial public reporting of Lazarus Group's activities targeting financial institutions.
  2. 2016-03-01Involvement in the Bangladesh Bank heist, demonstrating large-scale financial theft capability.
  3. 2020-01-01Increased focus on cryptocurrency theft and DeFi protocols.

10Reaction and fallout

Public reaction

The attacks prompted global calls for stronger international cyber cooperation and sanctions against state-sponsored cybercrime. Governments increased funding for critical infrastructure defense.

Political impact

The incidents highlighted the vulnerability of the global financial system to non-state and state-sponsored actors, increasing geopolitical tension between the DPRK and Western powers.

Geopolitical consequences

The attacks solidified the narrative of North Korea as a primary source of cyber instability, leading to increased sanctions and military posturing in the region.

11Legal

While specific criminal prosecutions are rare due to jurisdiction issues, the attacks have contributed to the development of international legal frameworks for cyber warfare and financial crime.

Civil lawsuits

  • Class-action lawsuits against financial institutions following major breaches.

12Aftermath

Policy changes

  • Increased mandatory reporting requirements for critical infrastructure (e.g., NERC CIP standards).

Regulatory changes

  • Stricter international guidelines for SWIFT messaging and cross-border financial transfers.

Security improvements

  • Mandatory implementation of Multi-Factor Authentication (MFA) across critical services.
  • Enhanced network segmentation and Zero Trust Architecture adoption.

13Significance and legacy

Significance

Lazarus Group represents a critical evolution in cyber threat history, demonstrating the successful fusion of state intelligence objectives with sophisticated, profit-driven criminal methodologies. It established a precedent for using cybercrime as a primary source of foreign currency for sanctioned regimes.

Legacy

The group's activities forced the global financial and security sectors to treat cybercrime not merely as a technical issue, but as a core geopolitical and economic threat, leading to the creation of specialized cyber defense agencies and international financial monitoring bodies.

14Disclosure and media

Authentication
Technical forensic analysis and network traffic correlation

Media partners

  • Reuters
  • The New York Times
  • BBC

Publishing organisations

  • Mandiant
  • United States Department of Treasury

15Related files

Related events

  • Sony Pictures Entertainment hack (2014)
  • Bangladesh Bank Heist (2016)

16Field notes

  1. 01The group has been known to use the same infrastructure and malware components for both espionage and purely criminal activities.
  2. 02Their attacks often involve compromising the supply chain of small, trusted vendors to gain access to larger, high-value targets.

17Resolution

The group's operations are constantly monitored and countered by international intelligence and private security firms, but its core threat remains active.

18Sources

Official documents

  • US Treasury Department Sanctions Lists
  • Mandiant Threat Reports

References

  1. [1]Mandiant Threat Intelligence Reports
  2. [2]United States Department of Treasury Reports
  3. [3]Reuters Investigative Journalism
Fact sheetEL-0049

Dates

Event
1 Jan 2009
Started
1 Jan 2009
Discovered
1 Jan 2009
Disclosed
1 Jan 2013
Ongoing
Yes

Target

Organisation
Global Financial and Tech Targets
Type
Mixed
Sector
Finance, Technology, Media, Government
Country
Global
Gov. level
Federal

Actor

Name
Lazarus Group
Type
Nation-State Actor
Nationality
North Korea
Nation-state
Democratic People's Republic of Korea (DPRK)
Affiliation
Ministry of People's Armed Forces (MPAF)
Motivation
Financial gain, geopolitical destabilization, and support for the North Korean regime.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Varies widely; from small intelligence packets to large financial transaction records.
Sensitivity
Top Secret
Published
No

Money

Crypto
Bitcoin, Monero, Ethereum

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.