Lazarus Hacking Group is a apt_group tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 14, 2025; most recent activity November 14, 2025.
The Lazarus Hacking Group is a North Korea–linked APT threat actor (often referred to as Lazarus Group/Hidden Cobra) known for high-profile intrusions and cyber campaigns against private-sector targets. The recent case where five individuals pleaded guilty to helping North Koreans infiltrate US firms underscores the group’s ongoing operational activity and the US government's enforcement actions against North Korea–backed cyber operations.
Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…
South Korean authorities suspect that North Korea's Lazarus Group was behind a hack of Upbit, resulting in losses of approximately $30.4 million. The breach involved unusual activity in Solana tokens and led Upbit to…