North Korean nation-state threat actor Lazarus Group targets global government and financial sectors via spearphishing and wiper malware.
Analyst brief
Lazarus Group (HIDDEN COBRA) is a North Korean nation-state threat actor active since 2009, targeting government and private sectors globally, including South Korea, the US, and financial institutions. They employ TTPs such as spearphishing attachments for initial access, credential dumping from LSASS memory, C2 over Web Protocols, and wiper malware like Destover and Qilin for destructive operations. Defenders should prioritize email security, network monitoring for anomalies, and immutable backups of critical systems.
Lazarus Group
Operation DarkSeoulDark SeoulHidden Cobra
activenation-state
Since 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltration of data while others have been disruptive in nature. Commercial reporting has referred to this activity as Lazarus Group and Guardians of Peace. Tools and capabilities used by HIDDEN COBRA actors include DDoS botnets, keyloggers, remote access tools (RATs), and wiper malware. Variants of malware and tools used by HIDDEN COBRA actors include Destover, Duuzer, and Hangman.
origin (suspected)
🇰🇵North Korea· state-sponsoredattribution confidence: medium (50)
target countries (as stated by the source)
South KoreaBangladesh BankSony Pictures EntertainmentUnited States