Incidents
Lazarus Group
Review stories that name this actor, with reporting mentions kept distinct from attribution of an operation.
News reporting onlyThis profile is assembled only from stories in this tracker’s reporting corpus. A mention measures this tracker’s coverage and is not attribution of an operation.
Named in 9 stories by this tracker. Population: 256 news stories with stored actor tags in this tracker corpus.
Catalogued identity
These references are curated crosswalk entries, not claims made by any feed. They describe the group, not the stories above.
MITRE catalogues 93 techniques for this group.
MITRE ATT&CK names and links © The MITRE Corporation.
Stories that name this actor
- DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
- Risky Bulletin: Expired credit cards can be used for malicious transactions
- Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
- FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
- North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
- Tracking Advanced Persistent Threat Groups | Recorded Future
- [tl;dr sec] #331 - How Adversaries Use AI, Skill Issues, Using IDEs for C2
- Agentic Attacks Have Already Hit Finance. The Defense Architecture Hasn't Caught Up.
- Threat Landscape Report: Uncovering Critical Cyber Threats to Hospitality and Recreation