95
Sophistication
2008
First Seen
85
Notoriety
92
Stealth
93
Immersive Rating
94
Impact
88
Tactics Variety
Group of blue-skinned figures with glowing green eyes in orange hoods stand before a large building at sunset.

Lazarus Group

A North Korean state-linked threat group known for a blend of espionage, cyber-crime, and destructive operations. This group was behind major incidents, including the Sony Pictures hack and the WannaCry ransomware outbreak. Highly resourced, adaptive, and capable across financial theft, supply-chain compromise, and espionage.

Key behaviours to watch:

  • Spear-phishing delivering custom loaders (e.g., Manuscrypt, AppleJeus) for credential theft and remote access.
  • Long-term persistence using DLL side-loading, scheduled tasks, and compromised VPN accounts.
  • Financial operations involving crypto-exchange compromise, mixer abuse, and multi-stage laundering chains.

Immersive coverage includes:

R00tk1t ISC CyberTeam hacktivist group with mysterious figure and stats on cyber attacks.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
R00TK1T ISC CyberTeam
40
2023
50
41
55
40
42
Salt Typhoon character made of water with salt shakers, stats, and info on Chinese APT hacking group.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
Salt Typhoon
95
2021
89
98
97
94
83
Illustration of a mechanical sandworm with a data panel about Sandworm Team cyberattack group and Intel source.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
Sandworm Team
95
2009
86
96
96
97
89
Illustration of a spider-headed figure in a hooded sweatshirt hacking on a laptop in a dark room.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
Scattered Spider
85
2022
90
77
86
90
48
Cartoon crocodile in tech suit with neon lights using control panel, labeled Sector 16 Intel with stats and description.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
Sector 16
57
2025
41
59
51
45
66
Dark hooded figure with skull face and swirling shadows labeled SocGhoulish, North Korean malware group.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
SocGhoulish
48
2018
50
53
63
66
68
StrongPity profile with stats and a muscular bald man holding a bowl with green flame.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
StrongPity
75
2012
50
55
42
60
70
Card labeled Transparent Tribe with leopard in hooded cloak holding staff and espionage threat stats.Brand logo with blue shapes and the word immersive above the text Learn More on black background.
Transparent Tribe
70
2013
65
68
45
67
64