Lazarus Group

☆ pin
MITRE G0009Also known as LABYRINTH CHOLLIMA, Labyrinth Chollima, APT38, Guardians of Peace, Bureau 121, Andariel, Moonstone Sleet, Lazarus Group
Reports
14
First seen
Mar 31, 2023
Last seen
Aug 13, 2026
Motivation
Espionage, Financial

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
South Korea ×1

Top ATT&CK techniques

T1566 Phishing ×10T1190 Exploit Public-Facing Application ×7T1486 Data Encrypted for Impact ×6T1204 User Execution ×4T1547 Boot or Logon Autostart Execution ×4T1078 Valid Accounts ×4T1005 Data from Local System ×3T1583 Acquire Infrastructure ×3T1070.001 Indicator Removal: Clear Windows Event Logs ×3T1041 Exfiltration Over C2 Channel ×3T1195 Supply Chain Compromise ×3T1598 Phishing for Information ×3

Indicators

cve ×30domain ×11ip_v4 ×9filename ×8ethereum_address ×3

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

High

North Korean Remote Workers Infiltrating Government and Businesses: Detection and Prevention

The Hacker News
Critical

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The Hacker News
High

Microsoft Patch Tuesday: 419 vulnerabilities in August as AI accelerates bug discovery

The Record (Recorded Future News)
High

CISA orders federal agencies to patch Windows vulnerability exploited by North Korean hackers in job-targeting campaign

The Record (Recorded Future News)
Critical

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

The Hacker News
High

U.S. and South Korean agencies warn of Gunra ransomware-as-a-service gang targeting critical infrastructure

CyberScoop
Critical

Lazarus Group sharing cyberattack tools with Gunra ransomware operators targeting South Korea

The Record (Recorded Future News)
High

June 2026 CVE Landscape: 60 High-Impact Vulnerabilities Actively Exploited

Recorded Future Insikt
High

CrowdStrike 2026 Technology Threat Landscape Report: China's Ambitions Fuel Attacks

CrowdStrike Blog
High

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

The Hacker News
High

The Evolving Linux Threat Landscape

Huntress Blog
Medium

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

ESET WeLiveSecurity
High

Cyber Brief October 2025 – Espionage, Disruption, Data Breaches, and Supply Chain Threats

CERT-EU Threat Intel
High

3CX Supply Chain Compromise: Contextualizing Events and Enabling Defense

Huntress Blog

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.