U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the Central District of California.
- Primary Target Sector: Media and Entertainment, Financial Services, Healthcare.
- Documented Financial Loss: $1.3 billion.
- 6 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Targeted spearphishing emails with weaponized attachments targeting Sony Pictures Entertainment employees, followed by fraudulent SWIFT banking credentials targeting the Bangladesh Central Bank, and weaponization of EternalBlue in WannaCry.
Operational & Financial Fallout
Extorted and destroyed Sony Pictures studio servers (forcing the cancellation of the theatrical premiere of The Interview); stole $81 million from the Bangladesh Central Bank via fraudulent SWIFT wire transfers; and paralyzed 300,000+ computers across 150 countries with WannaCry, forcing the UK National Health Service to divert emergency ambulances.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Targeted spearphishing emails with weaponized attachments targeting Sony Pictures Entertainment employees, followed by fraudulent SWIFT banking credentials targeting the Bangladesh Central Bank, and weaponization of EternalBlue in WannaCry.
Adversary Kill Chain Flow
5 Documented PhasesLazarus operatives sent spearphishing emails disguised as job inquiries and resume submissions to corporate personnel, containing malicious document macros that dropped the Brambul and Destover backdoors.
Operatives traversed corporate networks, compromising domain controllers and staging destructive disk-wiping payloads across file shares and production database clusters.
The Destover malware wiped master boot records, destroyed system files, and published private executive emails, unreleased movies, and employee Social Security numbers to public file-sharing sites.
Lazarus operatives breached the Bangladesh Central Bank network, harvesting SWIFT alliance terminal credentials to issue 35 fraudulent wire transfer orders totaling $951 million, successfully stealing $81 million.
Operatives combined the NSA EternalBlue SMB exploit with a cryptographic ransomware payload, releasing WannaCry. The worm spread uncontrollably across 300,000 computers worldwide in hours until a security researcher registered its kill-switch domain.
Extorted and destroyed Sony Pictures studio servers (forcing the cancellation of the theatrical premiere of The Interview); stole $81 million from the Bangladesh Central Bank via fraudulent SWIFT wire transfers; and paralyzed 300,000+ computers across 150 countries with WannaCry, forcing the UK National Health Service to divert emergency ambulances.
Procedural & Incident Timeline
Criminal complaint filed charging Park Jin Hyok with computer fraud and wire fraud conspiracies.
Treasury sanctions Park Jin Hyok and front company Chosun Expo Joint Venture.
Unsealing of superseding indictment adding co-conspirators Jon Chang Hyok and Kim Il.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Park Jin Hyok | Democratic People's Republic of Korea | fugitive | Pending | None | Lazarus Group computer programmer charged with WannaCry, Sony Pictures attack, and Bangladesh Bank heist. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1485 | Data Destruction Impact | "The Sony Pictures attack used the Destover wiper to destroy master boot records and overwrite hard drives, rendering thousands of workstations permanently inoperable." | Criminal Complaint ¶ 42, Page 27 | reviewed |
| T1486 | Data Encrypted for Impact Impact | "Park and his co-conspirators developed and distributed the WannaCry ransomware worm that infected over 230,000 computers across 150 nations within days." | Criminal Complaint ¶ 88, Page 61 | reviewed |
| T1021.002 | SMB / Windows Admin Shares Lateral Movement | "WannaCry automated its spread using the EternalBlue SMB exploit code to compromise unpatched Windows servers." | Criminal Complaint ¶ 92, Page 64 | reviewed |
| T1027 | Obfuscated Files or Information Defense Evasion | "Park and his co-conspirators heavily obfuscated WannaCry and Destover binaries with custom XOR encoders and commercial packers." | Criminal Complaint ¶ 63, Page 42 | reviewed |
| T1001.002 | Steganography Command and Control | "Lazarus malware disguised executable payloads inside benign PNG image files using steganographic pixel modification algorithms." | Criminal Complaint ¶ 74, Page 51 | reviewed |
| T1068 | Exploitation for Privilege Escalation Privilege Escalation | "WannaCry automated exploitation of kernel pool memory corruption via EternalBlue to execute ring 0 shellcode." | Criminal Complaint ¶ 94, Page 66 | reviewed |
View 1 Proposed / Unverified Mapping Candidates
"Spearphishing emails were sent to bank officials at Bangladesh Bank directing them to fake SWIFT messaging updates."