Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0032
MITRE ATT&CK Group

Lazarus Group (G0032)

Labyrinth ChollimaHIDDEN COBRAGuardians of PeaceZINCNICKEL ACADEMYDiamond Sleet
ShareXLinkedInRedditHN

[Lazarus Group](https://attack.mitre.org/groups/G0032) is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber Groups September 2019) [Lazarus Group](https://attack.mitre.org/groups/G0032) has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by [Lazarus Group](https://attack.mitre.org/groups/G0032) correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.(Citation: Novetta Blockbuster) North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.(Citation: Mandiant DPRK Laz Org Breakdown 2022)(Citation: Mandiant DPRK Groups 2023)(Citation: JPCert Blog Laz Subgroups 2025)

▪Techniques used (94)

T1059.003Windows Command ShellT1566.001Spearphishing AttachmentT1202Indirect Command ExecutionT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolT1001.003Protocol or Service ImpersonationT1584.004ServerT1105Ingress Tool TransferT1218.005MshtaT1010Application Window DiscoveryT1587.001MalwareT1134.002Create Process with TokenT1021.004SSHT1098Account ManipulationT1564.001Hidden Files and DirectoriesT1485Data DestructionT1591Gather Victim Org InformationT1106Native APIT1078Valid AccountsT1027.009Embedded PayloadsT1012Query RegistryT1090.002External ProxyT1027.013Encrypted/Encoded FileT1104Multi-Stage ChannelsT1046Network Service DiscoveryT1005Data from Local SystemT1489Service StopT1016System Network Configuration DiscoveryT1588.004Digital CertificatesT1573.001Symmetric CryptographyT1082System Information DiscoveryT1033System Owner/User DiscoveryT1620Reflective Code LoadingT1041Exfiltration Over C2 ChannelT1102.002Bidirectional CommunicationT1560Archive Collected DataT1203Exploitation for Client ExecutionT1059.001PowerShellT1566.002Spearphishing LinkT1074.001Local Data StagingT1036.003Rename Legitimate UtilitiesT1047Windows Management InstrumentationT1071.001Web ProtocolsT1557.001Name Resolution Poisoning and SMB RelayT1057Process DiscoveryT1547.001Registry Run Keys / Startup FolderT1685Disable or Modify ToolsT1589.002Email AddressesT1561.001Disk Content WipeT1491.001Internal DefacementT1588.002ToolT1547.009Shortcut ModificationT1059.005Visual BasicT1542.003BootkitT1218.011Rundll32T1583.006Web ServicesT1056.001KeyloggingT1571Non-Standard PortT1132.001Standard EncodingT1189Drive-by CompromiseT1110.003Password SprayingT1204.002Malicious FileT1553.002Code SigningT1218System Binary Proxy ExecutionT1560.002Archive via LibraryT1027.007Dynamic API ResolutionT1070.004File DeletionT1090.001Internal ProxyT1008Fallback ChannelsT1140Deobfuscate/Decode Files or InformationT1680Local Storage DiscoveryT1561.002Disk Structure WipeT1583.001DomainsT1053.005Scheduled TaskT1566.003Spearphishing via ServiceT1036.005Match Legitimate Resource Name or LocationT1070Indicator RemovalT1083File and Directory DiscoveryT1574.013KernelCallbackTableT1055.001Dynamic-link Library InjectionT1585.001Social Media AccountsT1021.001Remote Desktop ProtocolT1529System Shutdown/RebootT1124System Time DiscoveryT1036.004Masquerade Task or ServiceT1070.006TimestompT1070.003Clear Command HistoryT1574.001DLLT1686.003Windows Host FirewallT1543.003Windows ServiceT1021.002SMB/Windows Admin SharesT1585.002Email AccountsT1049System Network Connections DiscoveryT1560.003Archive via Custom MethodT0865Spearphishing Attachment

▪Software used (26)

S0364RawDisktoolS0238ProxysvcmalwareS0245BADCALLmalwareS0181FALLCHILLmalwareS0366WannaCrymalwareS1182MagicRATmalwareS0376HOPLIGHTmalwareS0263TYPEFRAMEmalwareS0567DtrackmalwareS0431HotCroissantmalwareS0246HARDRAINmalwareS0497DaclsmalwareS0271KEYMARBLEmalwareS0586TAINTEDSCRIBEmalwareS0347AuditCredmalwareS0108netshtoolS0593ECCENTRICBANDWAGONmalwareS0584AppleJeusmalwareS0103routetoolS0520BLINDINGCANmalwareS0665ThreatNeedlemalwareS0180VolgmermalwareS0498CryptoisticmalwareS0174RespondertoolS0241RATANKBAmalwareS0239Bankshotmalware
G0032on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.