lazarusholic

Everyday is lazarus.dayβ

Lazarus Group (APT38) Explained: Timeline, TTPs, and Major Attacks

2025-10-18, PicusSecurity
https://www.picussecurity.com/resource/blog/lazarus-group-apt38-explained-timeline-ttps-and-major-attacks
#Lazarus

Contents

Lazarus Group (APT38) Explained: Timeline, TTPs, and Major Attacks
Most cyber threat groups usually stick to a single specialty—some focus on spying, others on stealing money, and some just want to wreak havoc. Lazarus Group? They do it all. This notorious group has made a name for itself by combining espionage, sabotage, and massive financial theft into a single, formidable operation. Active since at least 2009, Lazarus has been behind some of the most talked-about cyberattacks in recent history.
Also known as APT38 or Hidden Cobra, the Lazarus Group is widely linked to North Korea, with suspected connections to its Reconnaissance General Bureau. Analysts point to repeated patterns in their operations and technical overlaps as evidence of these ties. What sets Lazarus apart is their ability to run multiple types of operations at the same time—they're not just spies, they're thieves and saboteurs too. The group first emerged focusing on regional targets …

IoC

http://worker.co.kr
http://palgong-cc.co.kr
http://www.celasllc.com/checkupdate.php