Lazarus Group is a North Korean state-sponsored cyber threat actor conducting financially motivated intrusions, espionage, and destructive operations. Its cryptocurrency theft and other revenue-generating activities support North Korean operations and sanctions evasion. Associated tracking names include APT-C-26, Black Artemis, Diamond Sleet, Guardians of Peace, Labyrinth Chollima, Nickel Academy, Selective Pisces, TA404, TEMP.Hermit, UNC2970, and Zinc. HIDDEN COBRA is a broader U.S. government designation for North Korean malicious cyber activity rather than an exclusively Lazarus-specific name. APT38 is a separately tracked North Korean financial threat group that shares parts of the Lazarus and TEMP.Hermit malware arsenal. Lazarus operations target financial institutions, cryptocurrency exchanges and engineering professionals, software ecosystems, aerospace professionals, and media organizations. Major attributed operations include the destructive 2014 Sony Pictures attack, the 2016 Bangladesh Bank theft, and the 2017 WannaCry ransomware outbreak. Its software supply-chain activity includes malicious packages impersonating legitimate software components and the compromise of 3CX software using Gopuram malware. Its malware portfolio includes families targeting Windows and macOS. Initial-access methods include spearphishing with malicious Microsoft Word attachments, malicious software components, and exploitation of software vulnerabilities. Payloads use macro-contained shellcode, runtime decryption, manual in-memory loading, and reflective DLL injection. Persistence mechanisms include scheduled tasks and Windows services. Lateral movement includes RDP propagation and attempts to access Windows shares using weak passwords and generated administrator-account names. Malware supports command-shell execution, payload downloading, and data uploading, while encryption, encoding, masquerading, and self-deletion impede detection and analysis. Lazarus has demonstrated sophisticated kernel-level defense evasion through FudModule. This component exploits CVE-2021-21551 in a legitimately signed Dell driver using bring-your-own-vulnerable-driver techniques to undermine security callbacks, file-system monitoring, and forensic visibility. Lazarus also exploited the Windows zero-day CVE-2024-38193 in attacks targeting cryptocurrency engineering and aerospace professionals, using FudModule to conceal activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
95 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
78 malware families attributed to this actor across reporting.
73 additional families tracked in Mallory.
32 CVEs this actor has used in observed campaigns. 32 of them exploited in the wild.
Today, August 25, 2026, is the CISA KEV deadline requiring all Federal Civilian Executive Branch agencies to patch CVE-2026-68820, the underlying Windows WinSock driver flaw that ShieldBreak (CVE-2026-69414) bypasses. Check Point Research this week formally attributed exploitation of CVE-2026-68820 to North Korea's Lazarus Group as part of Operation Dream Job, where the group distributed a malicious PDF viewer called SecurityPDF to aerospace and defence targets alongside fake job offer lures, using the driver flaw to escalate from initial access to full SYSTEM privileges.
Lazarus compromet des installations Roundcube et des CMS vulnérables à CVE-2025-49113, en utilisant des identifiants issus de fuites sur le dark web.
HIDDEN COBRA is known to use vulnerabilities affecting various applications. These vulnerabilities include: CVE-2016-0034: Microsoft Silverlight 5.1.41212.0 Vulnerability.
The malware is a sophisticated, previously undocumented user-mode module that uses the BYOVD technique and leverages the CVE-2021-21551 vulnerability in a legitimate, signed Dell driver. After gaining write access to kernel memory, the module’s global goal is to blind security solutions and monitoring tools.
In early June, researchers discovered that the Lazarus group was exploiting a security flaw in Windows' AFD.sys driver to access sensitive system areas. The attackers also used Fudmodule malware to hide their activities from security software.
27 more CVEs tied to this actor tracked in Mallory.
5,519 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed responsibility for the $1.4 billion Bybit exploit. The article cites funds from that theft indirectly reaching Cryptomus and Heleket as an example of the processors’ exposure to illicit activity.
Mentioned as abusing a vulnerable Intel Ethernet diagnostics driver to disable endpoint detection and response (EDR). The content does not attribute the analyzed AI-analysis evasion malware to Lazarus.
Mentioned as background for abusing a vulnerable Intel Ethernet diagnostics driver to disable EDR. The content does not attribute the analyzed AI-evasion malware to Lazarus or identify its sponsor.
Mentioned as a historical comparison illustrating the evolution of driver-based attacks: from abuse of the vulnerable Dell dbutil_2_3.sys driver to exploitation of CVE-2024-21338 in the Windows appid.sys component.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.