Sicra Header Logo
  • Careers
  • About us
  • People
EnglishNorsk
Talk to us
  1. Knowledge
  2. Dictionary
Dictionary
min read

Lazarus

State-sponsored threat actors can combine espionage, destructive activity, and financially motivated cybercrime within the same operations. Lazarus shows how advanced cyber actors can use a wide range of methods and target governments, organizations, and financial assets. 

What is Lazarus?

Lazarus, also known as Lazarus Group, is a North Korean state-sponsored threat actor linked to the country’s Reconnaissance General Bureau (RGB). The group has been active since at least 2009 and is associated with cyber operations involving espionage, destructive attacks, and financially motivated activity.

In public reporting, the name Lazarus is often used as an umbrella term for several North Korean cyber operators. These operators may share personnel, infrastructure, malware, and tradecraft, which can make it difficult to attribute individual operations to one specific group with confidence.

Lazarus has targeted governments, defense and technology organizations, financial institutions, and the cryptocurrency sector. The group has used methods including phishing, fake job opportunities, and malware to gain access to targets. North Korean actors associated with Lazarus have also conducted operations aimed at stealing cryptocurrency and other financial assets.

One well-known example is the 2014 cyberattack against Sony Pictures Entertainment, which U.S. authorities and security researchers have linked to North Korean actors and Lazarus.

Sicra and Lazarus

Sicra follows threat actors such as Lazarus, the organizations they target, and how their attack methods evolve. Knowledge about established threat actors can provide important context when analyzing security events and assessing which attack scenarios organizations should be prepared for.

One of our meeting rooms is named Lazarus. The name reflects our aim to keep the threat landscape close at hand and serves as a reminder of how varied the objectives and methods of an advanced threat actor can be, from espionage and sabotage to financially motivated cybercrime.

Services

Sicra SOC - Security Operation Center

Security maturity assessment

Security strategy


Related terms:
Threat actor, Fancy Bear, Anonymous, Threat intelligence, Malware, Phishing, Ransomware, Cyberattack, SOC (Security Operations Center), Cyber Kill Chain

Need Assistance?

We are happy to have a non-binding conversation. 
Contact us

Stay updated
Receive the latest news

Links
SustainabilityFAQPartnersCertifications and awardsCareerPress & brand
Contact
Tel: +47 648 08 488
E-mail: firmapost@sicra.no

Drammensveien 151, 0277 Oslo

Follow us on Instagram

Follow us on LinkedIn
Certifications
iso27001-white
ISO 27001 compliance
miljofyrtarnlogo-hvit-rgb
Eco-Lighthouse
iso9001-white-removebg-preview
ISO 9001 compliance
Sicra Footer Logo
Sicra © 2025
Privacy Policy