What is Lazarus?
Lazarus, also known as Lazarus Group, is a North Korean state-sponsored threat actor linked to the country’s Reconnaissance General Bureau (RGB). The group has been active since at least 2009 and is associated with cyber operations involving espionage, destructive attacks, and financially motivated activity.
In public reporting, the name Lazarus is often used as an umbrella term for several North Korean cyber operators. These operators may share personnel, infrastructure, malware, and tradecraft, which can make it difficult to attribute individual operations to one specific group with confidence.
Lazarus has targeted governments, defense and technology organizations, financial institutions, and the cryptocurrency sector. The group has used methods including phishing, fake job opportunities, and malware to gain access to targets. North Korean actors associated with Lazarus have also conducted operations aimed at stealing cryptocurrency and other financial assets.
One well-known example is the 2014 cyberattack against Sony Pictures Entertainment, which U.S. authorities and security researchers have linked to North Korean actors and Lazarus.
Sicra and Lazarus
Sicra follows threat actors such as Lazarus, the organizations they target, and how their attack methods evolve. Knowledge about established threat actors can provide important context when analyzing security events and assessing which attack scenarios organizations should be prepared for.
One of our meeting rooms is named Lazarus. The name reflects our aim to keep the threat landscape close at hand and serves as a reminder of how varied the objectives and methods of an advanced threat actor can be, from espionage and sabotage to financially motivated cybercrime.
Services
Sicra SOC - Security Operation Center
Security maturity assessment
Security strategy
Related terms: Threat actor, Fancy Bear, Anonymous, Threat intelligence, Malware, Phishing, Ransomware, Cyberattack, SOC (Security Operations Center), Cyber Kill Chain