G0032 · 116 ATT&CK techniques · 7 correlated reports

Lazarus Group

Aliases: Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet

Lazarus Group is a North Korean state-sponsored cyber threat group that has been attributed to the Reconnaissance General Bureau. The group has been active since at least 2009 and was reportedly responsible for the November 2014 destructive wiper attack against Sony Pictures Entertainment as part of a campaign named Operation Blockbuster by Novetta. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups, such as Andariel, APT37, APT38, and Kimsuky.

Open interactive actor investigation

ATT&CK techniques

T1059.003
Windows Command Shell
T1566.001
Spearphishing Attachment
T1202
Indirect Command Execution
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
T1001.003
Protocol or Service Impersonation
T1584.004
Server
T1105
Ingress Tool Transfer
T1218.005
Mshta
T1010
Application Window Discovery
T1587.001
Malware
T1134.002
Create Process with Token
T1021.004
SSH
T1098
Account Manipulation
T1564.001
Hidden Files and Directories
T1485
Data Destruction
T1591
Gather Victim Org Information
T1106
Native API
T1078
Valid Accounts
T1012
Query Registry
T1090.002
External Proxy
T1027.013
Encrypted/Encoded File
T1104
Multi-Stage Channels
T1046
Network Service Discovery
T1005
Data from Local System
T1489
Service Stop
T1016
System Network Configuration Discovery
T1588.004
Digital Certificates
T1573.001
Symmetric Cryptography
T1082
System Information Discovery
T1033
System Owner/User Discovery
T1620
Reflective Code Loading
T1041
Exfiltration Over C2 Channel
T1102.002
Bidirectional Communication
T1560
Archive Collected Data
T1203
Exploitation for Client Execution
T1059.001
PowerShell
T1566.002
Spearphishing Link
T1074.001
Local Data Staging
T1036.003
Rename System Utilities
T1047
Windows Management Instrumentation
T1071.001
Web Protocols
T1557.001
LLMNR/NBT-NS Poisoning and SMB Relay
T1057
Process Discovery
T1547.001
Registry Run Keys / Startup Folder
T1589.002
Email Addresses
T1561.001
Disk Content Wipe
T1491.001
Internal Defacement
T1588.002
Tool
T1547.009
Shortcut Modification
T1059.005
Visual Basic
T1542.003
Bootkit
T1218.011
Rundll32
T1583.006
Web Services
T1056.001
Keylogging
T1571
Non-Standard Port
T1132.001
Standard Encoding
T1189
Drive-by Compromise
T1110.003
Password Spraying
T1204.002
Malicious File
T1553.002
Code Signing
T1218
System Binary Proxy Execution
T1560.002
Archive via Library
T1027.007
Dynamic API Resolution
T1070.004
File Deletion
T1090.001
Internal Proxy
T1008
Fallback Channels
T1140
Deobfuscate/Decode Files or Information
T1562.001
Disable or Modify Tools
T1561.002
Disk Structure Wipe
T1583.001
Domains
T1562.004
Disable or Modify System Firewall
T1053.005
Scheduled Task
T1566.003
Spearphishing via Service
T1036.005
Match Legitimate Name or Location
T1070
Indicator Removal
T1083
File and Directory Discovery
T1574.013
KernelCallbackTable
T1055.001
Dynamic-link Library Injection
T1585.001
Social Media Accounts
T1021.001
Remote Desktop Protocol
T1529
System Shutdown/Reboot
T1124
System Time Discovery
T1036.004
Masquerade Task or Service
T1070.006
Timestomp
T1070.003
Clear Command History
T1574.002
DLL Side-Loading
T1543.003
Windows Service
T1021.002
SMB/Windows Admin Shares
T1585.002
Email Accounts
T1049
System Network Connections Discovery
T1560.003
Archive via Custom Method
T1584.001
Domains
T1027.002
Software Packing
T1204.001
Malicious Link
T1087.002
Domain Account
T1591.004
Identify Roles
T1567.002
Exfiltration to Cloud Storage
T1583.004
Server
T1608.002
Upload Tool
T1110
Brute Force
T1593.001
Social Media
T1220
XSL Script Processing
T1534
Internal Spearphishing
T1221
Template Injection
T1218.010
Regsvr32
T1497.001
System Checks
T1614.001
System Language Discovery
T1036
Masquerading
T1608.001
Upload Malware
T1588.003
Code Signing Certificates
T1218.001
Compiled HTML File
T1496
Resource Hijacking
T1547.005
Security Support Provider
T1003.001
LSASS Memory
T1112
Modify Registry
T1059
Command and Scripting Interpreter

Correlated CTI and IR reports

Continue the investigation