Lazarus Group
Actor Profile
Key Findings
- OriginAttributed to North Korea's Reconnaissance General Bureau, active since at least 2009; functions as both a broad umbrella and a label for narrower related clusters.
- Primary TargetCryptocurrency exchanges and DeFi platforms, plus software developers and IT job seekers, with defense, aerospace, and South Korean finance/telecom as secondary espionage targets.
- Initial AccessFake job offers and staged interviews (Contagious Interview), compromised upstream software dependencies, and AI-enabled spearphishing including deepfakes.
- Primary ObjectiveDual mandate of espionage/disruption and financially motivated cybercrime, with cryptocurrency theft increasingly used as a sanctions-evasion funding mechanism.
- Operating MethodDelivers credential/wallet stealers and a backdoor via malicious hiring-process packages, then manipulates transaction approvals and rapidly launders proceeds through mixers and chain-hopping.
- Defense PrioritiesSandbox code from hiring exercises, require multi-party approval on high-value transactions, audit upstream wallet/custody dependencies, and screen against DPRK-linked wallet designations.
Kill Chain & MITRE ATT&CK Mapping
Lazarus runs two parallel playbooks that converge on the same goal: long-term access followed by asset extraction, whether the objective is intelligence or cryptocurrency.
Initial Access
Fake recruiters lure software developers through a staged interview process, ultimately convincing the candidate to run a malicious npm package or take-home coding "test" as part of the hiring exercise.
Trusted vendor and upstream software dependencies, such as multi-signature wallet infrastructure, are compromised to reach a downstream high-value target rather than attacking it directly.
Highly targeted spearphishing, increasingly augmented with AI-generated deepfakes and more convincing pretexting, is used to compromise individual employees' sessions, credentials, and private keys.
They get in through fake job interviews, compromised software vendors, or highly targeted, AI-assisted phishing.
Execution
A JavaScript-based credential and cryptocurrency wallet stealer delivered through malicious packages as part of the Contagious Interview campaign.
A Python backdoor providing persistent access and data exfiltration capability, typically deployed alongside BeaverTail once initial access is established.
Once a target runs the malicious code, it steals credentials and wallet data, then installs a backdoor for lasting access.
Defense Evasion
Legitimate tools such as PowerShell are used alongside heavy code obfuscation, including "Matryoshka"-style nested obfuscation, to evade signature-based security tooling.
Command and control traffic is layered with additional encryption inside an already-encrypted SSL tunnel, complicating network-based detection.
They hide inside normal-looking traffic and heavily obscured code to slip past security tools.
Persistence
Long-term access is maintained through standard persistence mechanisms rather than exotic techniques, prioritizing durability and low visibility over cleverness.
They keep their access simple and durable rather than clever, favoring standard Windows mechanisms that are easy to overlook.
Impact
Once positioned inside exchange or wallet infrastructure, the group manipulates the transaction approval process so legitimate signers unknowingly authorize a malicious transfer, then rapidly launders proceeds through mixing services and chain-hopping to evade tracing.
They trick legitimate approvers into authorizing a fraudulent transfer, then launder the stolen funds fast to stay ahead of tracing.
Indicators of Compromise
Given the group's split focus, indicators vary meaningfully between its espionage and cryptocurrency theft tracks. These are the more durable, publicly reported patterns.
Reported patterns & behavior
| Indicator / Behavior | Type | Notes |
|---|---|---|
| Unsolicited recruiter contact requesting a take-home coding test | Behavior | Core Contagious Interview lure pattern |
| Malicious npm/PyPI package installed as part of a "hiring exercise" | Behavior | Delivery vector for BeaverTail and InvisibleFerret |
| BeaverTail / InvisibleFerret process activity | Malware family | JavaScript stealer paired with a Python backdoor |
| ThreatNeedle or RustBucket sample on endpoint | Malware family | Associated with Windows and macOS focused espionage campaigns |
| Anomalous multi-signature wallet approval request | Behavior | Consistent with transaction manipulation preceding a large crypto theft |
| Rapid post-theft chain-hopping or mixer usage | Blockchain behavior | Standard laundering pattern following a confirmed exchange or DeFi compromise |
No single indicator confirms Lazarus, but a fake hiring process followed by a malicious package install is one of the group's most consistent, recognizable patterns.
Detection & Mitigation Priorities
Ordered by impact-to-effort ratio, with distinct guidance for software organizations and cryptocurrency platforms.
- P1Sandbox and vet any code from an external interview or hiring exercise before running it on a developer's primary machine.
- P1Require independent, multi-party verification for high-value transaction approvals, especially for multi-signature wallets and exchange cold-to-hot wallet transfers.
- P1Audit third-party and upstream software dependencies used in wallet and custody infrastructure for supply chain compromise.
- P2Train staff to recognize AI-enabled social engineering, including deepfake voice or video used in recruiting or vendor impersonation.
- P2Monitor for known malware families (BeaverTail, InvisibleFerret, ThreatNeedle) using current threat intelligence feeds.
- P3Screen against OFAC and DPRK-linked wallet designations before processing large or first-time withdrawals.
Sandboxing hiring-related code and requiring multi-party approval on large transfers closes off the group's two most reliable entry points.
References
- 01Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, Diamond Sleet (Group G0032)MITRE ATT&CK
- 02The Lazarus Group and DPRK Crypto Theft in 2026: What Compliance Teams Need to Knowsanctions.io
- 03Lazarus Group: North Korea's Notorious Cyber Threat ActorCyble
- 04Lazarus Group: North Korea's Most Prolific APT Threat ActorGroup-IB
- 05APT Profile: Lazarus GroupCYFIRMA
- 06Lazarus Group: Attacks, Tactics, Malware & DefenseDeepStrike
- 07Lazarus GroupWikipedia