Lazarus Group (APT38) Explained: Timeline, TTPs, and Major Attacks
2025-10-18 • Picus Security •
Picus profiles Lazarus Group, also known as APT38 or Hidden Cobra, as a North Korea-linked threat group active since at least 2009 across espionage, sabotage, and financial theft operations. The overview ties the group to major activity including the Sony Pictures wiper attack, the Bangladesh Bank SWIFT theft, WannaCry, FASTCash, AppleJeus, and the Ronin Bridge cryptocurrency theft. Its ATT&CK mapping highlights spear-phishing through services, drive-by compromise, trojanized cryptocurrency applications, WMI abuse, startup-folder persistence, DLL side-loading, KernelCallbackTable manipulation, and exploitation of Windows privilege-escalation flaws. The technical examples describe payload obfuscation with packers, dynamic API resolution, embedded or encrypted payloads, RDP-based lateral movement, local staging of collected data, and C2 patterns used across Lazarus operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | palgong-cc.co.kr | 2018-02-12 | 2025-10-18 |
| DOMAIN | worker.co.kr | 2018-01-31 | 2025-10-18 |