CASE DOSSIER fugitive

U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)

Docket: 2:18-mj-01479 Court: U.S. District Court for the Central District of California Opened: 2018-06-08 Sector: Media and Entertainment, Financial Services, Healthcare

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$1.3 billion
Attempted to steal over $1.3 billion in cash and cryptocurrency, including the $81 million Bangladesh Bank heist and extensive WannaCry disruptions across NHS hospitals.
Techniques
6
Verified mappings
Defendants
1
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Central District of California.
  • Primary Target Sector: Media and Entertainment, Financial Services, Healthcare.
  • Documented Financial Loss: $1.3 billion.
  • 6 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Targeted spearphishing emails with weaponized attachments targeting Sony Pictures Entertainment employees, followed by fraudulent SWIFT banking credentials targeting the Bangladesh Central Bank, and weaponization of EternalBlue in WannaCry.

Operational & Financial Fallout

Extorted and destroyed Sony Pictures studio servers (forcing the cancellation of the theatrical premiere of The Interview); stole $81 million from the Bangladesh Central Bank via fraudulent SWIFT wire transfers; and paralyzed 300,000+ computers across 150 countries with WannaCry, forcing the UK National Health Service to divert emergency ambulances.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Targeted spearphishing emails with weaponized attachments targeting Sony Pictures Entertainment employees, followed by fraudulent SWIFT banking credentials targeting the Bangladesh Central Bank, and weaponization of EternalBlue in WannaCry.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Access Targeted Spearphishing Attachments
MITRE ATT&CK T1566.001 →

Lazarus operatives sent spearphishing emails disguised as job inquiries and resume submissions to corporate personnel, containing malicious document macros that dropped the Brambul and Destover backdoors.

Artifacts & Tooling: Destover backdoor Brambul worm Malicious Word macros
2
Privilege Escalation & Staging Domain Controller Domination and Wiper Staging
MITRE ATT&CK T1078 →

Operatives traversed corporate networks, compromising domain controllers and staging destructive disk-wiping payloads across file shares and production database clusters.

Artifacts & Tooling: Domain administrator compromise Batch script execution
3
Destructive Wiper Detonation Sony Pictures Wiper and Data Leak
MITRE ATT&CK T1485 →

The Destover malware wiped master boot records, destroyed system files, and published private executive emails, unreleased movies, and employee Social Security numbers to public file-sharing sites.

Artifacts & Tooling: Destover wiper MBR corruption Public leak dumps
4
Financial Cyber Heist Bangladesh Bank SWIFT Credential Compromise
MITRE ATT&CK T1041 →

Lazarus operatives breached the Bangladesh Central Bank network, harvesting SWIFT alliance terminal credentials to issue 35 fraudulent wire transfer orders totaling $951 million, successfully stealing $81 million.

Artifacts & Tooling: SWIFT alliance terminal compromise Custom PDF reader malware Printer manipulation
5
Global Ransomware Worm WannaCry 2.0 EternalBlue Epidemic
MITRE ATT&CK T1486 →

Operatives combined the NSA EternalBlue SMB exploit with a cryptographic ransomware payload, releasing WannaCry. The worm spread uncontrollably across 300,000 computers worldwide in hours until a security researcher registered its kill-switch domain.

Artifacts & Tooling: WannaCry.exe EternalBlue (CVE-2017-0144) Kill-switch domain check
Real-World Blast Radius & Operational Fallout

Extorted and destroyed Sony Pictures studio servers (forcing the cancellation of the theatrical premiere of The Interview); stole $81 million from the Bangladesh Central Bank via fraudulent SWIFT wire transfers; and paralyzed 300,000+ computers across 150 countries with WannaCry, forcing the UK National Health Service to divert emergency ambulances.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Implement out-of-band dual verification and hardware token security for all financial wire transfers and SWIFT terminals.
✓ Deploy endpoint application allowlisting to prevent execution of unverified wiper and ransomware binaries.
✓ Disable SMBv1 and promptly apply critical security patches across all network devices.
✓ Educate staff on identifying spearphishing attempts disguised as employment and business communications.

Procedural & Incident Timeline

2018-06-08 indictment

Criminal complaint filed charging Park Jin Hyok with computer fraud and wire fraud conspiracies.

2018-09-06 sanction

Treasury sanctions Park Jin Hyok and front company Chosun Expo Joint Venture.

2021-02-17 indictment

Unsealing of superseding indictment adding co-conspirators Jon Chang Hyok and Kim Il.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Park Jin Hyok Democratic People's Republic of Korea fugitive Pending None Lazarus Group computer programmer charged with WannaCry, Sony Pictures attack, and Bangladesh Bank heist.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1485 Data Destruction
Impact
"The Sony Pictures attack used the Destover wiper to destroy master boot records and overwrite hard drives, rendering thousands of workstations permanently inoperable." Criminal Complaint ¶ 42, Page 27 reviewed
T1486 Data Encrypted for Impact
Impact
"Park and his co-conspirators developed and distributed the WannaCry ransomware worm that infected over 230,000 computers across 150 nations within days." Criminal Complaint ¶ 88, Page 61 reviewed
T1021.002 SMB / Windows Admin Shares
Lateral Movement
"WannaCry automated its spread using the EternalBlue SMB exploit code to compromise unpatched Windows servers." Criminal Complaint ¶ 92, Page 64 reviewed
T1027 Obfuscated Files or Information
Defense Evasion
"Park and his co-conspirators heavily obfuscated WannaCry and Destover binaries with custom XOR encoders and commercial packers." Criminal Complaint ¶ 63, Page 42 reviewed
T1001.002 Steganography
Command and Control
"Lazarus malware disguised executable payloads inside benign PNG image files using steganographic pixel modification algorithms." Criminal Complaint ¶ 74, Page 51 reviewed
T1068 Exploitation for Privilege Escalation
Privilege Escalation
"WannaCry automated exploitation of kernel pool memory corruption via EternalBlue to execute ring 0 shellcode." Criminal Complaint ¶ 94, Page 66 reviewed
View 1 Proposed / Unverified Mapping Candidates
T1566.002: Spearphishing Link Proposed by rule

"Spearphishing emails were sent to bank officials at Bangladesh Bank directing them to fake SWIFT messaging updates."

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo), No. 2:18-mj-01479 (U.S. District Court for the Central District of California 2018), https://cybercaselibrary.com/cases/us-v-park-jin-hyok-lazarus/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-park-jin-hyok-lazarus" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>