DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-28
groupactive

Lazarus Group (APT38 / Hidden Cobra / BlueNoroff)

KNOWN ALIASES: APT38 · HIDDEN COBRA · BlueNoroff · Stardust Chollima · Zinc · Labyrinth Chollima
EXECUTIVE INTELLIGENCE SUMMARY

Prolific state-backed cyber warfare and financial cyber-heist collective responsible for billions in cryptocurrency theft, defense espionage, and disruptive attacks.

Operating under the Reconnaissance General Bureau (RGB), Lazarus blends destructive malware capabilities with sophisticated financial fraud, targeting cryptocurrency exchanges, DeFi protocols, defense contractors, and SWIFT banking networks globally.

MAJOR ATTRIBUTED OPERATIONS
2025 · Operation Cross-Chain BreachTARGET: Multi-Chain Liquidity Bridges

Exfiltration of $340M in digital assets utilizing social engineering over developer messaging channels and trojanized Web3 SDKs.

2022 · Ronin Network Bridge ExploitationTARGET: Sky Mavis / Axie Infinity

Compromise of validator private keys resulting in $620M asset extraction.

2016 · Bangladesh Bank Cyber HeistTARGET: Federal Reserve Bank of NY / Bangladesh Central Bank

Fraudulent SWIFT order injection attempting to steal $951M ($81M successfully moved).

2014 · Sony Pictures Entertainment Cyber AttackTARGET: Sony Pictures

Destructive wiper attack destroying internal corporate infrastructure and leaking unreleased films.

SOURCE CITATIONS & ATTESTATIONS (2)
US Department of Justice Indictment (Park Jin Hyok et al.)US District Court Central District of California

United States v. Jon Chang Hyok et al.

Mandiant Threat Intelligence APT38 Special DossierMandiant

APT38: Un-bankable State-Sponsored Financial Cybercrime

TELEMETRY CARDID: group-lazarus
ENTITY TYPE
group
STATE JURISDICTION / ORIGIN
Democratic People’s Republic of Korea (DPRK)
INDEXED TAGS
#apt#dprk#cryptocurrency_heist#financial_theft#defense_espionage#swift