Lazarus Group
MITRE G0009Also known as LABYRINTH CHOLLIMA, Labyrinth Chollima, APT38, Guardians of Peace, Bureau 121, Andariel, Moonstone Sleet, Lazarus Group
Reports
14
First seen
Mar 31, 2023
Last seen
Aug 13, 2026
Motivation
Espionage, Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Victim regions
South Korea ×1
Top ATT&CK techniques
T1566 Phishing ×10T1190 Exploit Public-Facing Application ×7T1486 Data Encrypted for Impact ×6T1204 User Execution ×4T1547 Boot or Logon Autostart Execution ×4T1078 Valid Accounts ×4T1005 Data from Local System ×3T1583 Acquire Infrastructure ×3T1070.001 Indicator Removal: Clear Windows Event Logs ×3T1041 Exfiltration Over C2 Channel ×3T1195 Supply Chain Compromise ×3T1598 Phishing for Information ×3
Indicators
cve ×30domain ×11ip_v4 ×9filename ×8ethereum_address ×3
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2026-68820 (exploited)CVE-2021-26829 (exploited)CVE-2021-26855 (exploited)CVE-2021-27076 (exploited)CVE-2021-27137 (exploited)CVE-2021-36260 (exploited)CVE-2022-27925 (exploited)CVE-2022-40684 (exploited)CVE-2022-41082 (exploited)CVE-2023-20198 (exploited)CVE-2023-32315 (exploited)CVE-2023-46747 (exploited)CVE-2024-21762 (exploited)CVE-2024-36401 (exploited)CVE-2016-4437 (exploited)CVE-2025-24472 (exploited)CVE-2025-27915 (exploited)CVE-2025-37899CVE-2025-41244 (exploited)CVE-2025-49113 (exploited)
Recent reports
High