Netskope Threat Labs

Lazarus

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Lazarus is a North Korean state sponsored threat group responsible for espionage, sabotage, and among the largest financial thefts in cyberspace. Its campaigns span destructive attacks, supply chain compromises, bank robberies, and large scale cryptocurrency theft, and its tooling spans Windows, Linux, and macOS malware. The group's operatives work in units that specialize in different objectives, and its operations continue to evolve with each disclosed campaign.

First seen
April 2022
Last seen
October 2026
Alert Name
DeepScan:Generic.DangerousPassword.Lazarus.D.FFFFFFFE
DeepScan:Generic.DangerousPassword.Lazarus.G.FFFFFFFE
Document-PDF.Trojan.Lazarus
Document-Word.Trojan.Lazarus
Dropped:Generic.DangerousPassword.Lazarus.D.B7D26142
Dropped:Generic.DangerousPassword.Lazarus.G.78D924B9
Dropped:Generic.DangerousPassword.Lazarus.G.AEE6B1C4
Dump:Generic.DangerousPassword.Lazarus.D.FFFFFFFE
Gen:Variant.MAC.Lazarus.12
Gen:Variant.MAC.Lazarus.13