Threat group.View on attack.mitre.org
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.
North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
Lazarus Group malware also uses a unique form of communication encryption known as FakeTLS that mimics TLS but uses a different encryption method, potentially evading SSL traffic inspection/decryption. |
| T1005 Data from Local System |
Lazarus Group has collected data and files from compromised networks. |
| T1008 Fallback Channels |
Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again. |
| T1010 Application Window Discovery |
Lazarus Group malware IndiaIndia obtains and sends to its C2 server the title of the window for each running process. The KilaAlfa keylogger also reports the title of the window in the foreground. |
| T1012 Query Registry |
Lazarus Group malware IndiaIndia checks Registry keys within HKCU and HKLM to determine if certain applications are present, including SecureCRT, Terminal Services, RealVNC, TightVNC, UltraVNC, Radmin, mRemote, TeamViewer, FileZilla, pcAnyware, and Remote Desktop. Another Lazarus Group malware sample checks for the presence of the following Registry key: |
| T1016 System Network Configuration Discovery |
Lazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card’s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available. |
| T1021.001 Remote Desktop Protocol |
Lazarus Group malware SierraCharlie uses RDP for propagation. |
| T1021.002 SMB/Windows Admin Shares |
Lazarus Group malware SierraAlfa accesses the |
| T1021.004 SSH |
Lazarus Group used SSH and the PuTTy PSCP utility to gain access to a restricted segment of a compromised network. |
| T1027.007 Dynamic API Resolution |
Lazarus Group has used a custom hashing method to resolve APIs used in shellcode. |
| T1027.009 Embedded Payloads |
Lazarus Group has distributed malicious payloads embedded in PNG files. |
| T1027.013 Encrypted/Encoded File |
Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names. |
| T1033 System Owner/User Discovery |
Various Lazarus Group malware enumerates logged-on users. |
| T1036.003 Rename Legitimate Utilities |
Lazarus Group has renamed system utilities such as |
| T1036.004 Masquerade Task or Service |
Lazarus Group has used a scheduled task named `SRCheck` to mask the execution of a malicious .dll. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.