EXPLORE
← Back to Actors

Lazarus Group

Lazarus GroupLabyrinth ChollimaHIDDEN COBRAGuardians of PeaceZINCNICKEL ACADEMYDiamond Sleet

[Lazarus Group](https://attack.mitre.org/groups/G0032) is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber Groups September 2019) [Lazarus Group](https://attack.mitre.org/groups/G0032) has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by [Lazarus Group](https://attack.mitre.org/groups/G0032) corre...

95
Techniques
86
Covered
9
Gaps
91%
Coverage
Coverage86/95

COVERED (86)

T1001.003Protocol or Service Impersonation2 det.T1005Data from Local System51 det.T1008Fallback Channels5 det.T1010Application Window Discovery1 det.T1012Query Registry25 det.T1016System Network Configuration Discovery41 det.T1021.001Remote Desktop Protocol54 det.T1021.002SMB/Windows Admin Shares74 det.T1021.004SSH35 det.T1027.009Embedded Payloads2 det.T1027.013Encrypted/Encoded File8 det.T1033System Owner/User Discovery62 det.T1036.003Rename Legitimate Utilities47 det.T1036.004Masquerade Task or Service7 det.T1036.005Match Legitimate Resource Name or Location45 det.T1041Exfiltration Over C2 Channel32 det.T1046Network Service Discovery52 det.T1047Windows Management Instrumentation88 det.T1048.003Exfiltration Over Unencrypted Non-C2 Protocol23 det.T1049System Network Connections Discovery23 det.T1053.005Scheduled Task100 det.T1055.001Dynamic-link Library Injection13 det.T1056.001Keylogging4 det.T1057Process Discovery23 det.T1059.001PowerShell376 det.T1059.003Windows Command Shell87 det.T1059.005Visual Basic70 det.T1070Indicator Removal65 det.T1070.003Clear Command History15 det.T1070.004File Deletion45 det.T1070.006Timestomp10 det.T1071.001Web Protocols81 det.T1074.001Local Data Staging10 det.T1078Valid Accounts306 det.T1082System Information Discovery88 det.T1083File and Directory Discovery48 det.T1090.001Internal Proxy10 det.T1090.002External Proxy8 det.T1098Account Manipulation245 det.T1102.002Bidirectional Communication16 det.T1105Ingress Tool Transfer191 det.T1106Native API29 det.T1110.003Password Spraying69 det.T1124System Time Discovery4 det.T1132.001Standard Encoding5 det.T1134.002Create Process with Token16 det.T1140Deobfuscate/Decode Files or Information58 det.T1189Drive-by Compromise12 det.T1202Indirect Command Execution58 det.T1203Exploitation for Client Execution80 det.T1204.002Malicious File461 det.T1218System Binary Proxy Execution261 det.T1218.005Mshta49 det.T1218.011Rundll3276 det.T1485Data Destruction97 det.T1489Service Stop58 det.T1491.001Internal Defacement4 det.T1529System Shutdown/Reboot18 det.T1542.003Bootkit4 det.T1543.003Windows Service80 det.T1547.001Registry Run Keys / Startup Folder53 det.T1547.009Shortcut Modification6 det.T1553.002Code Signing4 det.T1557.001Name Resolution Poisoning and SMB Relay23 det.T1560Archive Collected Data12 det.T1560.002Archive via Library1 det.T1561.001Disk Content Wipe2 det.T1561.002Disk Structure Wipe3 det.T1562.001Disable or Modify Tools325 det.T1562.004Disable or Modify System Firewall48 det.T1564.001Hidden Files and Directories25 det.T1566.001Spearphishing Attachment1055 det.T1566.002Spearphishing Link1086 det.T1566.003Spearphishing via Service102 det.T1571Non-Standard Port17 det.T1574.001DLL111 det.T1574.013KernelCallbackTable2 det.T1583.001Domains68 det.T1583.006Web Services1 det.T1587.001Malware10 det.T1588.002Tool13 det.T1588.004Digital Certificates1 det.T1589.002Email Addresses2 det.T1620Reflective Code Loading16 det.T1685Disable or Modify Tools281 det.T1686.003Windows Host Firewall20 det.