Avatier

Threat actor

Lazarus Group

Also known as APT38Source [2], BlueNoroffSource [2], Stardust ChollimaSource [2]

When it sanctioned the group in 2019, the U.S. Treasury described Lazarus Group as a North Korean state-sponsored hacking group controlled by the Reconnaissance General Bureau, North Korea's primary intelligence bureau.Source [1]

What authorities and investigators report

  • Treasury said Lazarus Group targets government, military, financial, manufacturing, media, entertainment and shipping organizations, as well as critical infrastructure, using cyber espionage, data theft, monetary heists and destructive malware operations.Source [1]
  • Treasury said Lazarus Group was involved in the WannaCry 2.0 ransomware attack, which the United States, Australia, Canada, New Zealand and the United Kingdom publicly attributed to North Korea in December 2017.Source [1]
  • Treasury said Lazarus Group was directly responsible for the 2014 cyber-attacks on Sony Pictures Entertainment.Source [1]
  • A 2022 FBI, CISA and Treasury advisory says that, as of April 2022, Lazarus Group actors had targeted firms and exchanges in the blockchain and cryptocurrency industry using spearphishing campaigns and malware to steal cryptocurrency.Source [2]
  • In the activity that advisory calls TraderTraitor, intrusions began with spearphishing messages to cryptocurrency company employees that often mimicked a recruitment effort, offering high-paying jobs to get recipients to download malware-laced applications.Source [2]

Techniques

Attack vectors

Sources

  1. Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups (sm774) — U.S. Department of the Treasury, 2019-09-13
  2. TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies (AA22-108A) — CISA, 2022-04-20

Last reviewed Oct 2, 2026