Lazarus

☆ pin
MITRE G0009Also known as APT38, HIDDEN COBRA
Reports
11
First seen
Oct 23, 2025
Last seen
Aug 12, 2026
Motivation
Espionage, Financial

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
South Korea ×1

Top ATT&CK techniques

T1566 Phishing ×6T1041 Exfiltration Over C2 Channel ×5T1547 Boot or Logon Autostart Execution ×4T1190 Exploit Public-Facing Application ×4T1068 Exploitation for Privilege Escalation ×4T1078 Valid Accounts ×3T1195 Supply Chain Compromise ×3T1021 Remote Services ×3T1557 Adversary-in-the-Middle ×2T1486 Data Encrypted for Impact ×2T1105 Ingress Tool Transfer ×2T1071 Application Layer Protocol ×2

Indicators

cve ×164filename ×31ip_v4 ×18domain ×15url ×14hash_sha1 ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.