Lazarus Hacking Group — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 14, 2025
Last Seen
November 14, 2025

Lazarus Hacking Group is a apt_group tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 14, 2025; most recent activity November 14, 2025.

Overview

The Lazarus Hacking Group is a North Korea–linked APT threat actor (often referred to as Lazarus Group/Hidden Cobra) known for high-profile intrusions and cyber campaigns against private-sector targets. The recent case where five individuals pleaded guilty to helping North Koreans infiltrate US firms underscores the group’s ongoing operational activity and the US government's enforcement actions against North Korea–backed cyber operations.

Related Threat Clusters

  • Five Plead Guilty in North Korean IT Worker Fraud Scheme

    Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…

    39 articles · Updated November 17, 2025
  • Lazarus Group Linked to $30M Upbit Hack in South Korea

    South Korean authorities suspect that North Korea's Lazarus Group was behind a hack of Upbit, resulting in losses of approximately $30.4 million. The breach involved unusual activity in Solana tokens and led Upbit to…

    100 articles · Updated November 28, 2025

Recent Intelligence Reports

  • Five plead guilty to helping North Koreans infiltrate US firms — Bleepingcomputer · November 14, 2025

CVSS v3.1 Breakdown