95
Sophistication
2008
First Seen
85
Notoriety
92
Stealth
93
Immersive Rating
94
Impact
88
Tactics Variety
Group of blue-skinned figures with glowing green eyes in orange hoods stand before a large building at sunset.

Lazarus Group

A North Korean state-linked threat group known for a blend of espionage, cyber-crime, and destructive operations. This group was behind major incidents, including the Sony Pictures hack and the WannaCry ransomware outbreak. Highly resourced, adaptive, and capable across financial theft, supply-chain compromise, and espionage.

Key behaviours to watch:

  • Spear-phishing delivering custom loaders (e.g., Manuscrypt, AppleJeus) for credential theft and remote access.
  • Long-term persistence using DLL side-loading, scheduled tasks, and compromised VPN accounts.
  • Financial operations involving crypto-exchange compromise, mixer abuse, and multi-stage laundering chains.

Immersive coverage includes:

Hooded figures with glowing purple eyes at laptops labeled IT Army of Ukraine, a volunteer cyber militia.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
IT Army of Ukraine
75
2013
68
72
88
65
70
Kamacite card with robotic worm image, stats, and text about its cyberattack role in Ukraine power grid.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
Kamacite
88
2013
86
83
85
81
86
Card titled Kimusky showing a winged armored horse figure and North Korean cyber espionage intel summary.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
Kimusky
62
2021
88
43
86
78
66
Brand logo with blue shapes and the word immersive above the text Learn More on black background.
Lapsus$
89
2009
92
73
85
81
87
Lazarus Group card with hooded figures, stats, and note on North Korea's hacking and cyberattacks.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
Lazarus Group
95
2008
85
92
93
94
88
Cartoon man in suit and monocle raising a wine glass with sinking ship labeled LULZ in water behind.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
LulzSec
50
2011
75
38
62
72
52
Magnallium intel card with a falcon dripping oil, symbolizing Iranian energy sector cyberattacks.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
MAGNALLIUM
80
2013
56
73
79
58
74
Stylized figure representing Onyx Sleet, a North Korea-aligned group targeting defense and IT sectors.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
Onyx Sleet
85
2014
80
80
84
71
77