created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
Lazarus Group
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G0032 |
| Aliases | Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet |
| Attribution | North Korea |
| Class | state |
| Active since | 2009 (per ATT&CK description) |
| ATT&CK entry created | 2017-05-31 |
| Techniques mapped | 119 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1001.003 |
Protocol or Service Impersonation |
T1005 |
Data from Local System |
T1008 |
Fallback Channels |
T1010 |
Application Window Discovery |
T1012 |
Query Registry |
T1016 |
System Network Configuration Discovery |
T1021.001 |
Remote Desktop Protocol |
T1021.002 |
SMB/Windows Admin Shares |
T1021.004 |
SSH |
T1027.007 |
Dynamic API Resolution |
T1027.009 |
Embedded Payloads |
T1027.013 |
Encrypted/Encoded File |
(First 12 of 119 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Apt38 — North Korea-linked actor, same attribution class
- Kimsuky — North Korea-linked actor, same attribution class
- Contagious Interview — North Korea-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G0032 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.