← All Actors

Lazarus Group (RGB, North Korea)

North Korea, Reconnaissance General Bureau (RGB)

Mission Type

Financial theft for regime revenue, coercive destruction for political signalling, espionage

Primary Sectors

FinanceMediaHealthcareTechnology

Operational Period

2009 – present

Attributed Cases

3

Attributed Cases

Activity Timeline

  1. 2014Sony PicturesDestructive
  2. 2016Bangladesh BankHybrid
  3. 2017WannaCryRansomware

Attribution Basis

How firmly each operation is tied to this actor, and by whom. Confidence reflects the weight of public evidence, not intelligence-community ground truth (see methodology §08).

Sony PicturesHigh Confidence

Attributed by US Government, US Government, Academic/Private Sector · Consequences: Sanctions, Indictment, Public Naming Only

Bangladesh BankHigh Confidence

Attributed by US Government, Academic/Private Sector · Consequences: Indictment, Sanctions

WannaCryHigh Confidence

Attributed by US Government, UK Government, Allied Coalition, Academic/Private Sector · Consequences: Sanctions, Indictment, Public Naming Only

TTP Pattern Summary

Lazarus demonstrates unusual operational breadth: destructive wipers (Sony), self-propagating ransomware (WannaCry), and sophisticated financial system manipulation (SWIFT heists). The group frequently exploits trusted third-party relationships and supply chain vectors. Financial operations show deep knowledge of banking settlement systems and cryptocurrency infrastructure.

Impact (4)Initial Access (2)Lateral Movement (2)Exfiltration (1)Defense Evasion (1)

Behavioural Signature

Lazarus is uniquely driven by financial objectives alongside political ones, reflecting DPRK's use of cyber operations to fund sanctioned programmes. The group shows high risk tolerance and limited concern for collateral damage, as demonstrated by WannaCry's indiscriminate global spread. Target selection oscillates between high-profile political coercion and systematic financial theft.

Governance Footprint

Subject to US DOJ indictments (Park Jin Hyok, 2018; three additional operatives, 2021), Treasury sanctions, and extensive UN Panel of Experts documentation of DPRK cyber-enabled sanctions evasion. Lazarus operations have been pivotal to debates on state-sponsored financial cybercrime and vulnerability equities.