← Back to all threat actors

Lazarus Group

Also known as Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet
Tracked as G0032

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.

How we source and review actor profiles
Motivation
nation-state
Attributed nexus
KP
Sectors
financial-services, cryptocurrency, defense, media-journalism
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: Labyrinth Chollima

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: HIDDEN COBRA

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Guardians of Peace

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: ZINC

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: NICKEL ACADEMY

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Diamond Sleet

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0032

Reviewed identity mapping approved on this date.

Cataloged
CVECVE-2021-44228 linked to this actor
Cataloged
CVECVE-2022-24521 linked to this actor
Cataloged
CVECVE-2023-29059 linked to this actor
Last observed
CampaignOperation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia,…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Lazarus GroupCanonical Name
Diamond SleetAlias
Guardians of PeaceAlias
HIDDEN COBRAAlias
Labyrinth ChollimaAlias
NICKEL ACADEMYAlias
ZINCAlias
G0032Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...