CARDS
CARDS
Lazarus Group is a highly adaptive state-sponsored threat actor, attributed to the North Korean Reconnaissance General Bureau (RGB), with activity documented as early as 2009. Initially engaging in cyber espionage and disruptive operations targeting South Korean entities, the group significantly evolved to become a primary generator of illicit revenue for the DPRK regime, driven by the critical need to bypass international sanctions and fund its strategic programs and military ambitions. This shift from primarily politically motivated attacks to financially driven cybercrime, particularly large-scale financial heists and cryptocurrency theft, sets Lazarus Group apart from many state-backed actors, making it a unique cyber-economic engine for its sponsor. While often referred to broadly, Lazarus Group encompasses several specialized subgroups, such as APT38 (Bluenoroff) focusing on financial crime and Andariel on espionage, which are sometimes used interchangeably or as umbrella terms for wider North Korean cyber operations.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Victim Count1
Not available
Information theft and espionage,Sabotage and destruction,Financial crime,Financial gain
Identity
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure1
Target Sectors1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| Operation Dream Job2 | Operation Dream Job (C0022) is attributed to Lazarus Group (G0032) by MITRE ATT&CK Campaigns. |
Indicators
SOCRadar reports 58115 IOCs for this profile. IntelliOS currently retains 53 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 4 source groups tracked; 1 currently contributes retained observable or context rows.
Retained Observables
Showing 53 of 53
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 5b40b73934c1583144f41d8463e227529fa7157e26e6012babd062e3fd7e0b035 | CISA AA22-108A |
| SHA-256 Hash | 60b3cfe2ec3100caf4afde734cfd5147f78acf58ab17d4480196831db4aa5f185 | CISA AA22-108A |
| SHA-256 Hash | 765a79d22330098884e0f7ce692d61c40dfcf288826342f33d976d8314cfd8195 | CISA AA22-108A |
| SHA-256 Hash | 867c8b49d29ae1f6e4a7cd31b6fe7e278753a1ba03d4be338ed11fd1efc7dd365 | CISA AA22-108A |
| SHA-256 Hash | 89b5e248c222ebf2cb3b525d3650259e01cf7d8fff5e4aa15ccd7512b1e639575 | CISA AA22-108A |
| SHA-256 Hash | 8acd7c2708eb1119ba64699fd702ebd96c0d59a66cba5059f4e089f4b09149255 | CISA AA22-108A |
| SHA-256 Hash | 9ba02f8a985ec1a99ab7b78fa678f26c0273d91ae7cbe45b814e6775ec4775985 | CISA AA22-108A |
| SHA-256 Hash | 9d9dda39af17a37d92b429b68f4a8fc0a76e93ff1bd03f06258c51b73eb40efa5 | CISA AA22-108A |
| SHA-256 Hash | dced1acbbe11db2b9e7ae44a617f3c12d6613a8188f6a1ece0451e4cd42051565 | CISA AA22-108A |
| SHA-256 Hash | e3d98cc4539068ce335f1240deb1d72a0b57b9ca5803254616ea4999b66703ad5 | CISA AA22-108A |
| SHA-256 Hash | f0e8c29e3349d030a97f4a8673387c2e21858cccd1fb9ebbf9009b27743b2e5b5 | CISA AA22-108A |
| SHA-1 Hash | 8e67006585e49f51db96604487138e688df732d35 | CISA AA22-108A |
| SHA-1 Hash | b2d9ca7b6d1bbbe4864ea11dfca343b7e15597d85 | CISA AA22-108A |
| SHA-1 Hash | f1606d4d374d7e2ba756bdd4df9b780748f6dc985 | CISA AA22-108A |
| MD5 Hash | 4e5ebbecd22c939f0edf1d16d68e84905 | CISA AA22-108A |
| MD5 Hash | 930f6f729e5c4d5fb52189338e549e5e5 | CISA AA22-108A |
| MD5 Hash | c2ea5011a91cd59d0396eb4fa8da7d215 | CISA AA22-108A |
| Filename | AlticGO.exe5 | CISA AA22-108A |
| Filename | CryptAIS.dmg5 | CISA AA22-108A |
| Filename | DAFOM-1.0.0.dmg5 | CISA AA22-108A |
| Filename | darwin64.bin5 | CISA AA22-108A |
| Filename | TokenAIS.app.zip5 | CISA AA22-108A |
| Filename | win32.bin5 | CISA AA22-108A |
| Network Indicator | aideck.net5 | CISA AA22-108A |
| Network Indicator | alticgo.com5 | CISA AA22-108A |
| Network Indicator | creaideck.com5 | CISA AA22-108A |
| Network Indicator | cryptais.com5 | CISA AA22-108A |
| Network Indicator | dafnefonseca.com5 | CISA AA22-108A |
| Network Indicator | dafom.dev5 | CISA AA22-108A |
| Network Indicator | esilet.com5 | CISA AA22-108A |
| Network Indicator | greenvideo.nl5 | CISA AA22-108A |
| Network Indicator | haciendadeclarevot.com5 | CISA AA22-108A |
| Network Indicator | infodigitalnew.com5 | CISA AA22-108A |
| Network Indicator | sche-eg.org5 | CISA AA22-108A |
| Network Indicator | tokenais.com5 | CISA AA22-108A |
| Network Indicator | www.vinoymas.ch5 | CISA AA22-108A |
| Network Indicator | https://aideck.net/board.php5 | CISA AA22-108A |
| Network Indicator | https://dafnefonseca.com/wp-content/themes/top.php5 | CISA AA22-108A |
| Network Indicator | https://greenvideo.nl/wp-content/themes/top.php5 | CISA AA22-108A |
| Network Indicator | https://haciendadeclarevot.com/wp-content/top.php5 | CISA AA22-108A |
| Network Indicator | https://infodigitalnew.com/wp-content/plugins/top.php5 | CISA AA22-108A |
| Network Indicator | https://sche-eg.org/plugins/top.php5 | CISA AA22-108A |
| Network Indicator | https://www.alticgo.com/update/5 | CISA AA22-108A |
| Network Indicator | https://www.esilet.com/update/5 | CISA AA22-108A |
| Network Indicator | https://www.vinoymas.ch/wp-content/plugins/top.php5 | CISA AA22-108A |
| Network Indicator | 104.168.98.1565 | CISA AA22-108A |
| Network Indicator | 108.170.55.2025 | CISA AA22-108A |
| Network Indicator | 199.188.103.1155 | CISA AA22-108A |
| Network Indicator | 38.132.124.1615 | CISA AA22-108A |
| Network Indicator | 45.14.227.585 | CISA AA22-108A |
| Network Indicator | 82.102.31.145 | CISA AA22-108A |
| Network Indicator | 89.45.4.1515 | CISA AA22-108A |
| Campaign Context | Thin Lazarus Group row backfilled from the same CISA TraderTraitor, MITRE G0032, and Google/Mandiant source set as the SOCRadar Lazarus card; IntelliOS preserves source-boundary notes around APT38 and related North Korea naming.5 | CISA AA22-108A |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar1 | 58115 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| CISA/FBI/Treasury5 | N/A | 53 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK2 | N/A | 0 | Context source retained; no direct observable rows retained from this source yet. |
| Google/Mandiant4 | N/A | 0 | Context source retained; no direct observable rows retained from this source yet. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Lazarus Group | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Lazarus Group | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor | Baseline actor-card corpus source for retained profile fields. |
| 2 | MITRE ATT&CK https://attack.mitre.org/groups/G0032 | Canonical ATT&CK group, campaign, software, aliases, and technique mapping source where matched. |
| 3 | MITRE CTI https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json | Open MITRE CTI source used for ATT&CK enrichment. |
| 4 | Google Cloud Security: APT Groups https://cloud.google.com/security/resources/insights/apt-groups | Threat Actor Profile |
| 5 | CISA AA22-108A: TraderTraitor North Korean APT targets blockchain companies https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a | IOC Source |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Lazarus Group, then compares naming and aliases against SOCRadar Actor Alias Index where collision checks exist.
The retained collision rows point to possible boundary questions involving Lazarus Group / Silent Chollima; Lazarus Group / UNC4736 based on shared evidence such as OperationTroy, Andariel; Citrine Sleet. These notes preserve reader context; IntelliOS does not automatically merge actor records.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| SOCRadar Actor Alias Index possible same actor | Lazarus Group / Silent Chollima | OperationTroy, Andariel | Retain as a source-boundary note; do not merge automatically. |
| SOCRadar Actor Alias Index possible same actor | Lazarus Group / UNC4736 | Citrine Sleet | Retain as a source-boundary note; do not merge automatically. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |