{
  "id": "case-lazarus-park-jin-hyok",
  "slug": "us-v-park-jin-hyok-lazarus",
  "title": "U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)",
  "summary": "Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.",
  "case_number": "2:18-mj-01479",
  "court": "U.S. District Court for the Central District of California",
  "district": "C.D. Cal.",
  "country": "United States",
  "opened_at": "2018-06-08",
  "status": "fugitive",
  "victim_sector": "Media and Entertainment, Financial Services, Healthcare",
  "victim_country": "United States, United Kingdom, Bangladesh, Philippines",
  "loss_amount_usd": 1300000000,
  "loss_amount_note": "Attempted to steal over $1.3 billion in cash and cryptocurrency, including the $81 million Bangladesh Bank heist and extensive WannaCry disruptions across NHS hospitals.",
  "first_seen_at": "2014-11-01T00:00:00Z",
  "last_updated_at": "2026-09-14T09:00:00Z",
  "actor_slug": "lazarus-group",
  "defendant_slugs": [
    "park-jin-hyok"
  ],
  "cves": [
    "CVE-2017-0144"
  ],
  "techniques": [
    {
      "technique_id": "T1485",
      "evidence_excerpt": "The Sony Pictures attack used the Destover wiper to destroy master boot records and overwrite hard drives, rendering thousands of workstations permanently inoperable.",
      "evidence_locator": "Criminal Complaint \u00b6 42, Page 27",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Data Destruction",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "Park and his co-conspirators developed and distributed the WannaCry ransomware worm that infected over 230,000 computers across 150 nations within days.",
      "evidence_locator": "Criminal Complaint \u00b6 88, Page 61",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1021.002",
      "evidence_excerpt": "WannaCry automated its spread using the EternalBlue SMB exploit code to compromise unpatched Windows servers.",
      "evidence_locator": "Criminal Complaint \u00b6 92, Page 64",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "SMB / Windows Admin Shares",
      "tactic": "Lateral Movement"
    },
    {
      "technique_id": "T1566.002",
      "evidence_excerpt": "Spearphishing emails were sent to bank officials at Bangladesh Bank directing them to fake SWIFT messaging updates.",
      "evidence_locator": "Complaint \u00b6 55",
      "mapping_status": "proposed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Spearphishing Link",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1027",
      "evidence_excerpt": "Park and his co-conspirators heavily obfuscated WannaCry and Destover binaries with custom XOR encoders and commercial packers.",
      "evidence_locator": "Criminal Complaint \u00b6 63, Page 42",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Obfuscated Files or Information",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1001.002",
      "evidence_excerpt": "Lazarus malware disguised executable payloads inside benign PNG image files using steganographic pixel modification algorithms.",
      "evidence_locator": "Criminal Complaint \u00b6 74, Page 51",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Steganography",
      "tactic": "Command and Control"
    },
    {
      "technique_id": "T1068",
      "evidence_excerpt": "WannaCry automated exploitation of kernel pool memory corruption via EternalBlue to execute ring 0 shellcode.",
      "evidence_locator": "Criminal Complaint \u00b6 94, Page 66",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Exploitation for Privilege Escalation",
      "tactic": "Privilege Escalation"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2018-06-08",
      "description": "Criminal complaint filed charging Park Jin Hyok with computer fraud and wire fraud conspiracies."
    },
    {
      "event_type": "sanction",
      "event_date": "2018-09-06",
      "description": "Treasury sanctions Park Jin Hyok and front company Chosun Expo Joint Venture."
    },
    {
      "event_type": "indictment",
      "event_date": "2021-02-17",
      "description": "Unsealing of superseding indictment adding co-conspirators Jon Chang Hyok and Kim Il."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Targeted spearphishing emails with weaponized attachments targeting Sony Pictures Entertainment employees, followed by fraudulent SWIFT banking credentials targeting the Bangladesh Central Bank, and weaponization of EternalBlue in WannaCry.",
    "blast_radius": "Extorted and destroyed Sony Pictures studio servers (forcing the cancellation of the theatrical premiere of The Interview); stole $81 million from the Bangladesh Central Bank via fraudulent SWIFT wire transfers; and paralyzed 300,000+ computers across 150 countries with WannaCry, forcing the UK National Health Service to divert emergency ambulances.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Targeted Spearphishing Attachments",
        "description": "Lazarus operatives sent spearphishing emails disguised as job inquiries and resume submissions to corporate personnel, containing malicious document macros that dropped the Brambul and Destover backdoors.",
        "technical_artifacts": [
          "Destover backdoor",
          "Brambul worm",
          "Malicious Word macros"
        ],
        "mitre_technique_id": "T1566.001"
      },
      {
        "phase": "Privilege Escalation & Staging",
        "title": "Domain Controller Domination and Wiper Staging",
        "description": "Operatives traversed corporate networks, compromising domain controllers and staging destructive disk-wiping payloads across file shares and production database clusters.",
        "technical_artifacts": [
          "Domain administrator compromise",
          "Batch script execution"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Destructive Wiper Detonation",
        "title": "Sony Pictures Wiper and Data Leak",
        "description": "The Destover malware wiped master boot records, destroyed system files, and published private executive emails, unreleased movies, and employee Social Security numbers to public file-sharing sites.",
        "technical_artifacts": [
          "Destover wiper",
          "MBR corruption",
          "Public leak dumps"
        ],
        "mitre_technique_id": "T1485"
      },
      {
        "phase": "Financial Cyber Heist",
        "title": "Bangladesh Bank SWIFT Credential Compromise",
        "description": "Lazarus operatives breached the Bangladesh Central Bank network, harvesting SWIFT alliance terminal credentials to issue 35 fraudulent wire transfer orders totaling $951 million, successfully stealing $81 million.",
        "technical_artifacts": [
          "SWIFT alliance terminal compromise",
          "Custom PDF reader malware",
          "Printer manipulation"
        ],
        "mitre_technique_id": "T1041"
      },
      {
        "phase": "Global Ransomware Worm",
        "title": "WannaCry 2.0 EternalBlue Epidemic",
        "description": "Operatives combined the NSA EternalBlue SMB exploit with a cryptographic ransomware payload, releasing WannaCry. The worm spread uncontrollably across 300,000 computers worldwide in hours until a security researcher registered its kill-switch domain.",
        "technical_artifacts": [
          "WannaCry.exe",
          "EternalBlue (CVE-2017-0144)",
          "Kill-switch domain check"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Implement out-of-band dual verification and hardware token security for all financial wire transfers and SWIFT terminals.",
      "Deploy endpoint application allowlisting to prevent execution of unverified wiper and ransomware binaries.",
      "Disable SMBv1 and promptly apply critical security patches across all network devices.",
      "Educate staff on identifying spearphishing attempts disguised as employment and business communications."
    ]
  }
}