The Lazarus Constellation: A Comprehensive Intelligence Dossier on the DPRK’s Cyber Warfare Apparatus (2009–2026)

2025-12-26 Falcon Feeds

https://falconfeeds.io/blogs/lazarus-constellation-dprk-cyber-warfare-intelligence-dossier-2009-2026

Thumbnail for The Lazarus Constellation: A Comprehensive Intelligence Dossier on the DPRK’s Cyber Warfare Apparatus (2009–2026)

FalconFeeds presents Lazarus Group as a DPRK state-backed threat apparatus under the Reconnaissance General Bureau with a hybrid mandate spanning espionage, sabotage, and revenue-generating cybercrime. The excerpt links Bureau 121, Unit 180, and the 110th Research Center to offensive hacking, financial cybercrime, technical research, vulnerability discovery, and malware development, supported by an academic and overseas IT-worker pipeline. It traces the group’s evolution from Operation Troy, Ten Days of Rain, DarkSeoul, and the Sony Pictures hack into SWIFT-focused bank heists, WannaCry, and cryptocurrency theft, including the reported $1.5 billion Bybit compromise in 2025. The dossier emphasizes TTPs such as DDoS, wiper malware, long-dwell network intrusion, fraudulent SWIFT transfers, ransomware worm propagation via EternalBlue, deepfake-enabled social engineering, and targeting of financial and defense-sector systems. Its DPRK relevance is direct because the text frames Lazarus cyber operations as an economic and strategic tool for sanctions evasion, weapons-program funding, and military modernization.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://ntsc.org/wp-content/upl… 2025-12-26 2025-12-26
URL https://right-hand.ai/blog/deep… 2025-12-26 2025-12-26
URL https://cdn.turdef.com/files/ar… 2025-12-26 2025-12-26
URL https://www.crowell.com/en/insi… 2025-12-26 2025-12-26
DOMAIN right-hand.ai 2025-12-26 2025-12-26
DOMAIN ntsc.org 2025-12-26 2025-12-26
DOMAIN cdn.turdef.com 2025-12-26 2025-12-26

Related Actors

Related Reports

« Back