Threat Group Profiling: Lazarus
2025-04-29 • S2W •
S2W profiles Lazarus as a North Korean state-backed APT linked to the Reconnaissance General Bureau and active since around 2009 under aliases including BlueNoroff, Andariel, Hidden Cobra, ZINC, and Diamond Sleet. The excerpt says Lazarus targets global organizations and enterprises for data theft, destructive activity, and cryptocurrency theft, with more than 25 major attacks estimated since January 2023. Initial access patterns include vulnerability exploitation, watering-hole compromises, phishing through email and social platforms, and supply-chain attacks such as the 3CX compromise. Common techniques include malicious macros, remote template injection, timestomping, indicator removal, reflective code loading, and DLL side-loading, underscoring why defenders should hunt for both entry vectors and post-compromise tradecraft.