Lazarus Group
Alias-Namen: Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet
4
2
14.05.2026
25.08.2026
Profil laut MITRE ATT&CK
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence.
Vollständiges MITRE-ProfilBeschreibung und Alias-Namen stammen aus MITRE ATT&CK®.
Nennungen im Zeitverlauf
Meldungen je Monat, letzte 12 Monate.
Beobachtete Techniken
ATT&CK-Techniken, die in denselben Meldungen benannt sind — nicht das vollständige MITRE-Repertoire.
T1587.001 Malware
Resource Development
T1588.001 Malware
Resource Development
T1566 Phishing
Initial Access
T1587.004 Exploits
Resource Development
T1588.005 Exploits
Resource Development
T1592.002 Software
Reconnaissance
T1053.005 Scheduled Task
Execution · Persistence · Privilege Escalation
T1059.001 PowerShell
Execution
T1102 Web Service
Command & Control
T1113 Screen Capture
Collection
T1204.002 Malicious File
Execution
T1218.010 Regsvr32
stealth
Gemeinsam genannt
Betroffene Branchen
Meldungen
CYFIRMA reports telecom sector faces high cyber risk as China, Russia-linked APT campaigns intensify
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
Kimsuky targets organizations with PebbleDash-based tools
Quellen: The Hacker News (2), Industrial Cyber (1), Securelist (1)
Alle Angaben auf dieser Seite stammen aus dem Alias-Abgleich der Meldungstexte gegen den MITRE-ATT&CK-Katalog. Beziehungen entstehen rein statistisch: Zwei Einträge gelten als verbunden, wenn sie in derselben Meldung benannt sind. Das ist keine eigenständige Attribution durch SecBoard, und eine Nennung ist kein Nachweis einer Täterschaft.