Lazarus Group
View MITRE Group Page ↗Key Facts
- Attributed Country: Democratic People's Republic of Korea.
- ATT&CK Group Reference: G0032 (Lazarus Group).
- Linked to 1 primary court prosecution records.
- Identified 1 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1485 Data Destruction | 1 incidents |
| T1486 Data Encrypted for Impact | 1 incidents |
| T1021.002 SMB / Windows Admin Shares | 1 incidents |
| T1566.002 Spearphishing Link | 1 incidents |
| T1027 Obfuscated Files or Information | 1 incidents |
| T1001.002 Steganography | 1 incidents |
| T1068 Exploitation for Privilege Escalation | 1 incidents |
Prosecution Cases Attributed to This Actor
U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)
Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.
Treasury OFAC Sanctions Actions
Decentralized cryptocurrency mixer used by the Lazarus Group to launder over $455 million in stolen crypto.
Official Treasury Press Release ↗North Korean state-sponsored hacking organization responsible for WannaCry, Sony Pictures hack, and crypto heists.
Official Treasury Press Release ↗Targeted Defensive Hardening for Lazarus Group
Primary Initial Access Defense
Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.
Lateral Movement Interception
Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.