MITRE ATT&CK G0032
Aliases: HIDDEN COBRA, Guardians of Peace, Zinc, APT38, Labyrinth Chollima
Official Attribution Source: U.S. Department of Justice Indictment (C.D. Cal.)

Key Facts

Jurisdiction
Democratic People's Republic of Korea
Geographic origin
Cases
1
Prosecution matters
Defendants
1
Indicted individuals
Sanctions
2
OFAC designations
  • Attributed Country: Democratic People's Republic of Korea.
  • ATT&CK Group Reference: G0032 (Lazarus Group).
  • Linked to 1 primary court prosecution records.
  • Identified 1 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to Lazarus Group Technique frequencies extracted from verified indictments for Lazarus Group. T1485 Data Destruction 1 incidents T1486 Data Encrypted for Impact 1 incidents T1021.002 SMB / Windows Admin Shares 1 incidents T1566.002 Spearphishing Link 1 incidents T1027 Obfuscated Files or Information 1 incidents T1001.002 Steganography 1 incidents T1068 Exploitation for Privilege Escalation 1 incidents
Technique frequencies extracted from verified indictments for Lazarus Group.
ATT&CK Techniques Mapped to Lazarus Group
Technique Frequency
T1485 Data Destruction 1 incidents
T1486 Data Encrypted for Impact 1 incidents
T1021.002 SMB / Windows Admin Shares 1 incidents
T1566.002 Spearphishing Link 1 incidents
T1027 Obfuscated Files or Information 1 incidents
T1001.002 Steganography 1 incidents
T1068 Exploitation for Privilege Escalation 1 incidents

Prosecution Cases Attributed to This Actor

fugitive 2018-06-08

U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)

Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.

7 techniques View case →

Treasury OFAC Sanctions Actions

Tornado Cash Virtual Currency Mixer 2022-08-08

Decentralized cryptocurrency mixer used by the Lazarus Group to launder over $455 million in stolen crypto.

Official Treasury Press Release ↗
Lazarus Group (Reconnaissance General Bureau) 2019-09-13

North Korean state-sponsored hacking organization responsible for WannaCry, Sony Pictures hack, and crypto heists.

Official Treasury Press Release ↗
OPERATIONAL DEFENSE

Targeted Defensive Hardening for Lazarus Group

Run Stack Audit →

Primary Initial Access Defense

Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.

Lateral Movement Interception

Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.