G0032

G0032Lazarus Group

Description

[Lazarus Group](https://attack.mitre.org/groups/G0032) is a North Korean state-sponsored cyber threat group that has been attributed to the Reconnaissance General Bureau.(Citation: US-CERT HIDDEN COBRA June 2017)(Citation: Treasury North Korean Cyber Groups September 2019) The group has been active since at least 2009 and was reportedly responsible for the November 2014 destructive wiper attack against Sony Pictures Entertainment as part of a campaign named Operation Blockbuster by Novetta. Malware used by [Lazarus Group](https://attack.mitre.org/groups/G0032) correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. (Citation: Novetta Blockbuster) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups, such as [Andariel](https://attack.mitre.org/groups/G0138), [APT37](https://attack.mitre.org/groups/G0067), [APT38](https://attack.mitre.org/groups/G0082), and [Kimsuky](https://attack.mitre.org/groups/G0094).

References

  1. https://attack.mitre.org/groups/G0032
  2. https://web.archive.org/web/20210723190317/https://adversary.crowdstrike.com/en-US/adversary/labyrinth-chollima/
  3. https://web.archive.org/web/20160226161828/https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Report.pdf
  4. https://www.secureworks.com/about/press/media-alert-secureworks-discovers-north-korean-cyber-threat-group-lazarus-spearphishing
  5. https://blogs.microsoft.com/on-the-issues/2017/12/19/microsoft-facebook-disrupt-zinc-malware-attack-protect-customers-internet-ongoing-cyberthreats/
  6. https://home.treasury.gov/news/press-releases/sm774
  7. https://www.us-cert.gov/ncas/alerts/TA17-164A
  8. https://www.us-cert.gov/ncas/analysis-reports/AR19-100A

Software attributed to this8

TypeTargetConfidenceTier
SoftwareRising Suns0448100%live
SoftwareDtracks0567100%live
SoftwareTorismas0678100%live
SoftwareDRATzaruss0694100%live
SoftwareRATANKBAs0241100%live
SoftwareCryptoistics0498100%live
SoftwareBankshots0239100%live
SoftwareAppleJeuss058495%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
APT38
Group
Andariel
Group
APT37
Group
Kimsuky
Actor
Operation Shadow Force
Software
holyghost
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.