body-backgroundbody-background

Epiphany Monitored Threat Actors: 361

The Epiphany Intelligence Platorm monitors all major cybercrime groups and their 1244 aliases as of June 14th, 2025. The Epiphany Intelligence Platform's threat actor data set is updated daily.

Search for names, descriptions and alias containing:

world mapNorth Korea

Labyrinth Chollima (Korea (Democratic People's Republic of))

Lazarus Group is a threat group that has been attributed to the North Korean government. The group has been active since at least 2009 and was reportedly responsible for the November 2014 destructive wiper attack against Sony Pictures Entertainment as part of a campaign named Operation Blockbuster by Novetta. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. In late 2017, Lazarus Group used KillDisk, a disk-wiping tool, in an attack against an online casino based in Central America.

North Korean group definitions are known to have significant overlap, and the name Lazarus Group is known to encompass a broad range of activity. Some organizations use the name Lazarus Group to refer to any activity attributed to North Korea. Some organizations track North Korean clusters or groups such as Bluenoroff, APT37, and APT38 separately, while other organizations may track some activity associated with those group names by the name Lazarus Group.


Goals:
Espionage, Sabotage

Target Industries:
Government, Private sector

Target Countries:
South Korea, Bangladesh Bank, Sony Pictures Entertainment, United States, Thailand, France, China, Hong Kong, United Kingdom, Guatemala, Canada, Bangladesh, Japan, India, Germany, Brazil, Thailand, Australia, Cryptocurrency exchanges in South Korea

Aliases:
Andariel, Appleworm, APT 38, APT-C-26, APT38, ATK117, ATK3, BeagleBoyz, Bluenoroff, Bureau 121, Citrine Sleet, COPERNICIUM, COVELLITE, Dark Seoul, DEV-0139, DEV-1222, Diamond Sleet, G0032, G0082, Group 77, Guardians of Peace, Hastati Group, Hidden Cobra, Lazarus Group, NewRomanic Cyber Army Team, Nickel Academy, NICKEL GLADSTONE, Operation AppleJeus, Operation DarkSeoul, Operation GhostSecret, Operation Troy, Sapphire Sleet, Stardust Chollima, Subgroup: Bluenoroff, TA404, Unit 121, Whois Hacking Team, Zinc

References:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65