Lazarus Group is a North Korean state-linked threat actor associated with long-running espionage, disruptive, destructive, and financially motivated cyber operations. Widely used aliases include Hidden Cobra, Zinc, Diamond Sleet, Labyrinth Chollima, Nickel Academy, Black Artemis, TA404, UNC2970, and Guardians of Peace; Famous Chollima is described as a subgroup or branch associated with Lazarus activity. The actor is known for developing and operating custom malware families and conducting campaigns across Windows, macOS, and Linux environments. The group has targeted government, defense, aerospace, security, financial, and technology-related organizations, as well as software supply chains and remote-work hiring channels. Reported activity includes industrial espionage against an Israeli security company, targeting of aerospace and defense organizations in India, France, Brazil, and Germany, and software supply-chain compromise through poisoned npm packages. Lazarus has also been linked to North Korean remote IT worker schemes used to infiltrate foreign companies, generate revenue, steal data, and potentially stage follow-on malware deployment. Observed tradecraft includes spearphishing with malicious Microsoft Word documents, abuse of signed Windows utilities such as regsvr32 and mshta for execution, PowerShell-based payload delivery, host and process reconnaissance, enumeration of logged-on users, downloading and executing additional binaries from command-and-control infrastructure, persistence via Startup folders and Registry Run keys, and encoded command-and-control traffic including Base64. Lazarus malware families have been documented collecting hostnames, usernames, operating system and CPU details, process lists, and other victim profiling data. Some Lazarus-associated malware also includes keylogging capability and supports remote control functions such as shell execution, script execution, process termination, and process injection. The actor’s operational profile spans espionage and revenue generation for the DPRK, with a demonstrated ability to adapt tooling and infrastructure across intrusion sets and subgroups. Lazarus remains one of the most prolific North Korean cyber operators, combining bespoke malware development, social engineering, supply-chain compromise, and post-exploitation tradecraft in support of state objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
81 malware families attributed to this actor across reporting.
76 additional families tracked in Mallory.
36 CVEs this actor has used in observed campaigns. 36 of them exploited in the wild.
The attacks have been discovered to take use of CVE-2026-68820 (CVSS score: 7.0), a privilege escalation vulnerability that affects the Windows Ancillary Function Driver for WinSock ("AFD.sys"), which Microsoft fixed as part of their August 2026 Patch Tuesday upgrades.
Lazarus compromet des installations Roundcube et des CMS vulnérables à CVE-2025-49113, en utilisant des identifiants issus de fuites sur le dark web.
In early June, we discovered a sample that was exploiting a new zero-day vulnerability within Winsock driver ( CVE-2024-38193 ) to achieve local privilege escalation to deploy a new version of FudModule rootkit.
Together they form a re-packaged exploit for Silverlight based on CVE-2016-0034 (MS16-006) – a Silverlight Memory Corruption vulnerability. The exploit has previously been used by several exploit kits including RIG and Angler to deliver multiple crimeware tools.
The group is known for spearphishing attacks, which include CVE-2015-6585, a zero-day vulnerability at the time of its discovery.
31 more CVEs tied to this actor tracked in Mallory.
5,300 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the parent North Korean threat group of Famous Chollima in connection with the fraudulent IT worker scheme.
Conducting cyber espionage via Operation Dream Job using fake recruiter/job lures, trojanized PDF viewers, DLL side-loading, and a Windows privilege-escalation exploit to deploy backdoors and maintain remote access in aerospace and defense targets.
Conducting a renewed Operation Dream Job campaign using fraudulent job offers to target defense and aerospace victims in Europe and India, exploiting a Windows zero-day for privilege escalation and deploying backdoors and a rootkit.
Referenced as potentially linked to active exploitation of CVE-2026-68820, a Windows Ancillary Function Driver for WinSock local privilege escalation vulnerability.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.