Threat Actor ProfileLazarus
The Lazarus Group, also known by aliases such as Hidden Cobra, APT38 or Labyrinth Chollima, is one of the most prolific, versatile and eccentric threat actors on the global stage. The advanced persistent threat (APT) group is believed to operate under the Reconnaissance General Bureau, North Korea’s primary intelligence agency. It is estimated that the group has around 3,300 members. Since emerging in the mid-2000s, Lazarus has been responsible for some of the most high-profile cyberattacks in the last decade, including the Sony breach (2014), Bangladesh bank heist (2016), WannaCry ransomware attacks (2017), as well as many of the well known heists on crypto exchanges. This page will provide an overview of the group's history and preferred tactics, as well as looking towards the future to see how this persistent threat actor may evolve in the years to come.
- Aliases: Hidden Cobra, APT38, Andariel, Unit 121, Bureau 121, NewRomanic Cyber Army Team, BlueNorOff, Labyrinth Chollima, Guardians of Peace, CTG-6459, TEMP.Hermit, T-APT15, Black Alicanto, TA444, TAG-71
- Strategic motives: Espionage, financial gain, disruption, destruction
- Affiliation: North Korean Reconnaissance General Bureau
- Cyber capabilities: ★★★★☆
- Target sectors: Aerospace, Banking & Investment Services, Biotech, BitCoin exchanges, Defense, Energy, Engineering, Financial, Government, Healthcare, Industrials, Media, Media & Publishing, Shipping and Logistics, Technology, Transportation
- Observed countries: Albania, Andorra, Argentina, Australia, Austria, Bangladesh, Belarus, Belgium, Bosnia, Bosnia and Herzegovina, Brazil, Bulgaria, Canada, Chile, China, Costa Rica, Croatia, Czech Republic, Denmark, Ecuador, Estonia, Finland, France, Germany, Ghana, Greece, Guatemala, Herzegovina, Holy See, Hong Kong, Hungary, Iceland, India, Indonesia, Ireland, Israel, Italy, Japan, Jordan, Kenya, Kuwait, Latvia, Liechtenstein, Lithuania, Luxembourg, Macau, Malaysia, Malta, Mexico, Moldova, Monaco, Mongolia, Montenegro, Mozambique, Nepal, Netherlands, Nicaragua, Nigeria, North Korea, North Macedonia, Norway, Pakistan, Panama, Peru, Philippines, Poland, Portugal, Romania, Russia, San Marino, Serbia, Singapore, Slovakia, Slovenia, South Africa, South Korea, Spain, Sweden, Switzerland, Taiwan, Tanzania, Thailand, Togo, Turkey, Uganda, Ukraine, United Kingdom, United States, Uruguay, Vietnam, Zambia
Request a free membership to access our full research insights
Already a member? Login here
Origins, Motivations & Targets
The earliest signs of the Lazarus group can be traced back to 2007, when North Korea was under the rule of Kim Jong Il, father of the current leader Kim Jong Un. It is believed that Lazarus was established as a cyber warfare unit under the Reconnaissance General Bureau (RGB), North Korea’s primary intelligence agency. During this period, the development of cyber capabilities was seen as essential to the regime’s asymmetric warfare strategy. Kim Jong Il was said to be an enthusiastic proponent of this, stating that “cyber-attacks are like atomic bombs” and that “war is won and lost by who has greater access to the adversary’s military technical information in peacetime.”[2] The Lazarus group’s earliest operations tended to focus on espionage and disruption, primarily targeting organizations in the United States and South Korea.
After the death of Kim Jong Il in 2011, Kim Jong Un sought to expand on his fathers’ vision and harness the state’s cyber capabilities to generate revenue for the sanction-hit regime. Starting in 2015, Lazarus began conducting financially motivated operations, first focusing on banks and later cryptocurrency exchanges. North Korea has a long history of using criminal activities, including counterfeiting, drug trafficking and insurance fraud, to support its struggling economy. With its growing cyber capabilities, shifting these efforts to cyberspace likely felt like a natural evolution.[3]
What makes Lazarus stand out from other APTs is the breadth and diversity of its operations; the group has targeted a wide range of sectors over the years, including but not limited to the aerospace, banking, pharmaceuticals, energy, healthcare, technology, education, and transportation sectors. The group’s targeting appears to shift in line with the regime’s ambitions, as well as external events such as the COVID-19 pandemic. The regime relies on espionage and information theft to bypass (often difficult and expensive) R&D processes that are required for the advancement and modernization of the state.
Additionally, Lazarus has repeatedly targeted governments and military organizations to obtain intelligence and undermine their adversaries. In 2016, the group breached South Korea’s Defense Ministry and reportedly obtained classified military documents outlining a joint US-South Korea combat strategy, including procedures to “decapitate” the North Korean leadership.[4] Such campaigns are used to strengthen North Korea’s strategic position and pre-empt threats from their regional neighbors.
Group structure
It should be noted that the Lazarus group is often used as an umbrella term referring to multiple North Korean cyber operators. Based on analysis of various toolsets and attack patterns, Lazarus can be divided into sub-groups with varying objectives. Two commonly cited sub-groups are BlueNorOff, which is believed to be the unit responsible for financially motivated attacks, and AndAriel, which focuses its operations on foreign businesses, government agencies, and financial services infrastructure. According to some estimates, BlueNorOff (also referred to as APT38) boasts approximately 1,700 members, while AndAriel has around 1,600 members.[5]
In addition to BlueNorOff and AndAriel, Mandiant designates an additional sub-group - TEMP.Hermit. This unit is believed to focus on strategic intelligence gathering and is known to have targeted organizations in the government, defense, telecommunications, and financial sectors. It is believed that these three units are subordinate to an agency named Lab 110, previously Bureau 121, which is known as North Korea’s primary hacking unit.[6]
However, it’s worth noting that due to the inherently clandestine nature of cyber threats, verifying this structure is no easy task. To complicate matters further, there are overlaps in tools and techniques between North Korea’s Kimsuky and APT37. This poses challenges for attribution and obscures our view of how these cyber teams are organized.
SWOT analysis
Strengths, weaknesses, opportunities & threats
Strengths
- Large arsenal of custom tools and malware
- Protection from North Korean leadership, limiting the impact of international legal action
- Proven expertise at reconnaissance and planning, allowing them to achieve sophisticated attacks
Weaknesses
- Tendency to reuse TTPs and repurpose tools and infrastructure
Opportunities
- Cryptocurrency platforms and exchanges provide new avenues for financially motivated attacks
Threats
- Information leaks by defectors
- Undermining of state propaganda by allowing cyber workers access to the Internet
Campaigns Overview
January 1, 2022
16:00 PM
Operation Troy
2009-2012
One of the earliest known campaigns linked to the Lazarus group is “Operation Troy”, which took place between 2009 and 2012. During this time, Lazarus orchestrated a string of Distributed Denial of Service (DDoS) attacks against South Korean and US targets in the government, news media, and financial sectors. The group is believed to have hijacked more than 20,000 computers (including 12,000 in South Korea) to create the botnet used to drive Internet traffic to the targeted sites. Although these attacks were relatively unsophisticated, Lazarus succeeded in its mission of disruption, resulting in some websites being offline for several days. In tandem, the group ran a multi-year reconnaissance and data exfiltration campaign, maintaining its focus on South Korean and US entities.[7]
Operation Troy occurred during a period of rising tensions on the Korean peninsula, fueled by missile strikes and nuclear tests in the North. South Korean officials were concerned about their neighbors' expanding cyber capabilities, speculating that cyberattacks could be used to disable the country’s telecoms system prior to military strikes.[8] These fears were not unfounded, as subsequent investigations have uncovered links between Operation Troy and two later campaigns: the 2011 “Ten Days of Rain” incident and the 2013 DarkSeoul attacks. South Korea was targeted on both occasions. Reconnaissance efforts undertaken during Operation Troy are believed to have provided a foundation for the distribution of the DarkSeoul wiper malware in subsequent years.[9]
January 1, 2022
16:00 PM
Sony hack
2014
Lazarus made international headlines in 2014 with its attack on the film studio Sony Pictures Entertainment, prompted by the upcoming release of "The Interview," a comedy depicting an assassination attempt on North Korean leader Kim Jong-un. The attack began on November 24, when Sony employees were met by the image of a skull on every screen, accompanied by threats to release sensitive data unless the attackers’ demands were met. It is believed that Lazarus obtained a massive 100 terabytes of Sony data, the text equivalent of roughly 2.5 million books. Over the next few weeks, the group leaked a trove of unreleased films, executive salaries, and even Sony employees’ private medical records, causing immense embarrassment and financial losses for the company. This prompted several employees to initiate class action lawsuits against Sony for failing to protect their personal information. A senior Sony executive, whose own private emails had been exposed, was forced to step down in the aftermath. Lazarus also threatened physical violence against theaters screening "The Interview," forcing Sony to cancel its release.[10]
The Sony hack is remembered as one of the first cyberattacks where physical damage was caused to the victim, thanks to the Lazarus group’s use of wiper malware. This destructive malware, identified as WhiskeyAlfa, was designed to eradicate the contents of any hard drive connected to an infected system.[11] To maximize impact, Lazarus also deployed ransomware inside Sony’s network. Links were eventually made between the malware used against Sony and other malware associated with North Korea, prompting the FBI to attribute the attack to Lazarus. Sony's losses from the attack and the cancellation of "The Interview" release were estimated to exceed $100 million. Amidst international pressure, Sony eventually decided to release the film on Christmas Day, both in theaters and through video-on-demand platforms. Then-US President Barrack Obama praised this decision, asserting that the US should not capitulate to cyber threats or engage in self-censorship due to the fear of offending foreign powers.[12]
January 1, 2022
16:00 PM
Heist on the Central Bank of Bangladesh
2016
Two years later, the Lazarus group once again captured global attention by orchestrating one of the most brazen bank heists in history. This time, their target was the central bank of Bangladesh, resulting in the theft of over $81 million. The attack began on February 4, 2016, when Lazarus hackers used malware known as SWIFT Client to access the bank’s SWIFT credentials, which could be used to communicate with other financial institutions and banks around the world. This enabled the hackers to send a series of transfer requests to the Federal Reserve Bank of New York, where Bangladesh Bank maintained a US-dollar account containing almost $1 billion. The fraudulent requests contained instructions to transfer all available funds to various accounts in the Philippines and Sri Lanka, which were disguised by using the names of fake charities and non-profit organizations. Because Lazarus had previously infiltrated Bangladesh Bank’s network using spear phishing, it appeared that the requests were made by a legitimate bank employee.[13]
Lazarus executed this attack with precision, choosing dates and times where communication between Bangladesh Bank and the Federal Reserve Bank of New York would be impeded. The first sign of suspicious activity was reported at Bangladesh Bank’s Dhaka office on Friday, February 5, when a printer used to document large international transfers stopped working. In Bangladesh, weekends take place on Friday and Saturdays, meaning that the bank was operating at reduced capacity. When employees noticed the broken printer, they chalked it up to a benign tech issue and didn’t attempt to reboot it until the following day. When the printer was eventually reinstated, it began to dispense the fraudulent transfer requests, alerting employees to the situation. They immediately tried to contact the Federal Reserve, but by then it was the weekend in the US. Unable to elicit a response, employees at Bangladesh Bank tried to block the transfers by contacting banks in the Philippines and Sri Lanka. However, this coincided with the Lunar New year holiday, meaning the banks were closed and the transfers could proceed. This strategy bought Lazarus five days to execute the attack with minimal interruption.[14]
Despite the technical sophistication and thorough planning demonstrated by the group, it was a simple spelling error that caused the house of cards to come tumbling down. Hackers misspelled “foundation” in the recipient NGO’s name as “fandation”, causing the routing bank to seek clarification from Bangladesh and allowing them to halt some of the transactions. At the same time, the unusually large number of payment instructions and the transfer requests to private entities was raising suspicions in New York. In total, the transactions that were stopped amounted to circa $870 million, leaving the hackers with just $81 million. Most of this money was never recovered, having been laundered through casinos in the Philippines.[15]
January 1, 2022
16:00 PM
WannaCry
2017
On May 12, 2017, a ransomware variant known as WannaCry spread like wildfire around the world, infecting more than 300,000 devices in 150 countries. WannaCry spread like a worm, using self-propagation through a remote exploit made public two months earlier. The exploit took advantage of a flaw in the Microsoft Windows implementation of the Server Message Block (SMB) protocol, known as EternalBlue. This vulnerability was initially discovered by the US National Security Agency (NSA), who developed the EternalBlue exploit for its own intelligence gathering purposes. This exploit was revealed to the public in early 2017 by the hacking group Shadow Brokers, who compromised the NSA and leaked a cache of exploits online. Just two months later it would be used to orchestrate one of the broadest and most damaging ransomware attacks in history.[16]
Several high-profile organizations were impacted by the spread of WannaCry, including the Spanish mobile company Telefónica, auto manufacturer Renault-Nissan, Russia’s Interior Ministry, and the UK’s National Health Service. In the case of the latter, hospitals, doctor’s surgeries, and ambulance services were disrupted for several days, endangering the lives of patients, and costing the UK’s national health service an estimated GBP 92 million.[17] It is likely that the impact would have been far worse if not for a serendipitous discovery by the British security researcher Marcus Hutchins, however. Hutchins, previously MalwareTech, discovered an unusual function when reversing the WannaCry malware. He noticed that before the malware was executed, it would query the domain iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com, which did not exist. He proceeded to register the domain, unintentionally triggering a “kill switch” which prevented WannaCry from executing on newly infected computers. This saved countless organizations around the world from having their files encrypted. Nonetheless, the worldwide disruption caused by WannaCry produced an estimated $8 billion in damages.[18] In the days following the attack, researchers at Symantec and Kaspersky identified links between WannaCry and Lazarus, noting code overlaps between WannaCry and previously identified Lazarus tools. In the months that followed, countries including the US, UK, and Canada attributed the attack to Lazarus.[19] For more technical details about WannaCry, check out Chapter 2 of our Definitive Guide to Ransomware.
January 1, 2022
16:00 PM
Operation Dream Job
2019-2023
Beginning in 2019, Lazarus launched a broad cyber-espionage campaign targeting companies in the aerospace and defense sectors, mostly located in Europe, the United States, and the Middle East. The group relied heavily on social engineering to pull off this campaign, leveraging LinkedIn and other messaging platforms to establish initial contact with their targets, who held technical and business-related job titles. The attackers created fake profiles to impersonate hiring managers from prominent US firms. The targets were then lured into opening and interacting with malicious documents, which triggered the execution of custom, multistage malware. This malware was designed to infiltrate the target’s systems and exfiltrate valuable information without detection. In 2023, Lazarus introduced Linux malware into the campaign, demonstrating an evolution in their tactics.[20] [21] To read more about Operation Dream Job, check out our blog: Cyber Siege on the Fourth Estate.
January 1, 2022
16:00 PM
Ronin Network hack
2022
As previously mentioned, the Lazarus group has intensified its targeting of the cryptocurrency industry in recent years. In 2022, the group managed to steal a whopping $600 million worth of Ethereum and $25.5 million of USDC stablecoin from Ronin Network, an EVM (Ethereum Virtual Machine)-compatible blockchain made for gaming. This marked one of the largest attacks on a decentralized finance system to date. Ronin Network is tied to Axie Infinity, a popular blockchain game developed by Vietnamese studio Sky Mavis. The attack involved Lazarus compromising Sky Mavis’s Ronin validator nodes and Axie DAO validator nodes, allowing the funds to be siphoned away in just two transactions. According to Sky Mavis, private keys obtained by Lazarus were used to forge fake withdrawals. At the time, five validator nodes were required for any deposit or withdrawal from the Ronin chain. In light of the attack, this number has since been increased to eight.[22]
North Korea is the global leader in cryptocurrency attacks. In 2022 alone, an estimated $1.7 billion was stolen by North Korean hackers, $1 billion of which was stolen from decentralized finance (DeFi) protocols. These stolen funds make up a significant chunk of the nation’s economy and are likely used to fund the country’s nuclear weapons programme. In recent years, several cryptocurrency mixers have been sanctioned by the US government for helping Lazarus and other North Korean groups to launder stolen funds. More information about this can be found in the Trends section.[23]
Lazarus in the Netherlands
In late 2021, an unnamed aerospace company in the Netherlands was targeted by one of the Lazarus group’s trademark recruitment scams. An employee was contacted by individuals posing as Amazon recruiters and lured into opening malicious documents sent via email and LinkedIn. Upon opening, various tools including droppers, loaders, and HTTP(S) backdoors were deployed on the victim’s systems. One notable aspect of this campaign was the group’s use of a user-mode component to exploit the CVE-2021-21551 vulnerability in a legitimate Dell driver, from which kernel memory could be written, marking the first recorded abuse of this vulnerability in the wild. The attackers leveraged their kernel memory write access to disable key Windows monitoring mechanisms, including registry tracking, file system monitoring, and event tracing. This effectively blinded security solutions, allowing Lazarus to roam freely without detection.[61] Such a sophisticated approach again highlights the group’s ability to conduct deep research and develop advanced exploitation techniques.
At Hunt & Hackett, we have observed the use of these techniques by Lazarus firsthand. In one of our previous investigations, we observed Lazarus sending highly targeted spear phishing messages disguised as job offers via the online messaging platform Telegram. As was the case with their 2021 campaign, tools such as loaders and backdoors were dropped onto the victim’s system once the malicious documents were opened.
The Netherlands was not the only country targeted in this particular operation. Research by ESET shows that this was part of a broader effort to steal valuable information from defense companies in France, Italy, Germany, Poland, Ukraine, Turkey, Qatar and Brazil. Lazarus has repeatedly targeted the defense sector over the years, likely driven by North Korea’s enduring obsession with military supremacy. The regime continues to utilize the Songun (military-first) policy framework enacted by Kim Jong Il in 1995, which prioritizes the Korean People’s Army (KPA) as the central institution of North Korean society. Under Songun, the military is given the highest priority in resource allocation and national affairs, as it is seen as the primary force for safeguarding the regime. Over the past 15 years, the North Korea has become increasingly dependent on APTs like Lazarus to support its military ambitions.[62] [63]
Trends
In recent years, the Lazarus Group has become the focus of international legal action. In September 2018, the US Department of Justice charged suspected Lazarus Group member Park Jin Hyok for his involvement in the WannaCry ransomware attacks, the Sony Pictures breach, and other cybercrimes. According to the affidavit, Park was charged with conspiring to gain unauthorized access to computers, obtaining information with intent to defraud, causing damage, extortion related to computer intrusion, and wire fraud.[64] In February 2021, a US federal indictment expanded on these charges, implicating two additional members - Jon Chang-Hyok, Kim Il - in a criminal conspiracy to conduct destructive cyberattacks, steal and extort over $1.3 billion from financial institutions and companies, create and deploy malicious cryptocurrency applications, and fraudulently market a blockchain platform.[65]
Individuals affiliated with the Lazarus group have also come under scrutiny. In 2021, Canadian-American citizen Ghaleb Alaumary pled guilty to aiding the Lazarus Group in laundering money obtained through ATM cash-out operations. In 2022, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned the virtual currency mixer Blender.io for aiding the Lazarus Group in laundering stolen virtual currency. This followed the group’s largest virtual currency heist to date, worth nearly $620 million, from a blockchain project linked to the online game Axie Infinity. Blender.io is believed to have processed more than $20.5 million of the illicit proceeds.[66] In the same year, the US sanctioned cryptocurrency mixer Tornado Cash for allowing the proceeds of cybercrime to be laundered on its platform, including nearly half a billion dollars stolen by Lazarus.[67]
The same year, US cryptocurrency researcher Virgil Griffith was sentenced to more than five years in prison for conspiring to help North Korea evade US sanctions using cryptocurrency. Griffith, who formerly worked for the Ethereum Foundation, traveled to North Korea in 2019 to speak at the Pyongyang Blockchain and Cryptocurrency Conference, despite being denied permission by the US Department of State to do so. US prosecutors said Griffith was aware the information he provided could be used to circumvent sanctions imposed on North Korea due to its nuclear weapons development. While speaking at the conference, Griffith stated: “The most important feature of blockchains is that they are open. And the DPRK [Democratic People's Republic of Korea] can't be kept out no matter what the USA or the UN says.”[68] This assessment, unfortunately, turned out to be correct. In the years that followed, Lazarus shifted focus from financial institutions to cryptocurrency platforms, stealing an estimated $3 billion over the course of 58 attacks.[69] UN sanction monitors believe these proceeds were used to further develop North Korea’s nuclear weapons program.[70]
Conclusions & Future Implications
The Lazarus Group remains one of the most formidable and versatile threat actors on the global stage. Their operations, characterized by a blend of espionage, financial theft, and disruptive attacks, reflect the strategic objectives of North Korea’s regime. Over the years, Lazarus has demonstrated an exceptional ability to adapt its tactics, techniques, and procedures to exploit emerging technologies and vulnerabilities. From the audacious Sony Pictures hack and the infamous WannaCry attack, to sophisticated heists targeting financial institutions and cryptocurrency platforms, the group’s activities have had significant global repercussions.
International efforts to counter Lazarus’s operations have intensified, resulting in multiple indictments and sanctions against individuals and entities associated with the group. However, these measures have had limited impact on the group’s capabilities, largely due to the protection and support they receive from North Korea’s leadership. The group’s continued focus on cryptocurrency platforms and the defense sector underscores their evolving strategy to circumvent traditional financial systems and fund the regime’s ambitions, including advancing its nuclear weapons program. As the group continues to evolve and expand its capabilities, the international community should remain vigilant, continuously updating detection measures, sharing technical information, and increasing awareness of the threats posed by this relentless and resourceful threat actor.
Sources
[2] https://ccdcoe.org/uploads/2019/06/CyCon_2019_BOOK.pdf
[4] https://edition.cnn.com/2017/10/10/politics/north-korea-hackers-us-south-korea-war-plan/index.html
[6] https://cloud.google.com/blog/topics/threat-intelligence/mapping-dprk-groups-to-government
[7] https://www.radware.com/cyberpedia/ddos-attacks/the-lazarus-group-apt38-north-korean-threat-actor/
[9] https://www.usna.edu/CyberCenter/_files/documents/Operation-Blockbuster-Report.pdf
[10] https://www.vox.com/2015/1/20/18089084/sony-hack-north-korea
[11] https://www.infosecinstitute.com/resources/mitre-attck/mitre-attck-disk-content-wipe/
[12] https://deadline.com/2014/12/sony-hack-timeline-any-pascal-the-interview-north-korea-1201325501/
[13] https://www.wired.com/2016/05/insane-81m-bangladesh-bank-heist-heres-know/
[14] https://nsarchive.gwu.edu/news/cyber-vault/2019-02-20/tainted-trove
[15] https://www.reuters.com/article/idUSKCN0WC0TB/
[16] https://www.wired.com/story/eternalblue-leaked-nsa-spy-tool-hacked-world/
[17] https://www.acronis.com/en-eu/blog/posts/nhs-cyber-attack/
[20] https://cymulate.com/threats/lazarus-group-adds-linux-malware-to-arsenal-in-operation-dream-job/
[21] https://web-assets.esetstatic.com/wls/2020/06/ESET_Operation_Interception.pdf
[22] https://therecord.media/more-than-625-million-stolen-in-defi-hack-of-ronin-network
[23] https://www.chainalysis.com/blog/2022-biggest-year-ever-for-crypto-hacking/
[24] https://www.secureops.com/wp-content/uploads/2021/06/Sony-Breach-Analysis-v4.pdf
[25] https://www.clearskysec.com/wp-content/uploads/2020/08/Dream-Job-Campaign.pdf
[26] https://www.trendmicro.com/en_us/research/17/b/ratankba-watering-holes-against-enterprises.html
[27] https://attack.mitre.org/groups/G0032/
[28] https://attack.mitre.org/techniques/T1053/005/
[30] https://x.com/ESETresearch/status/1458438155149922312
[35] https://web.archive.org/web/20160226161828/https:/www.operation
[36] https://attack.mitre.org/techniques/T1010/
[38] https://logrhythm.com/blog/a-technical-analysis-of-wannacry-ransomware/
[40] https://www.clearskysec.com/wp-content/uploads/2020/08/Dream-Job-Campaign.pdf
[43] https://attack.mitre.org/groups/G0032/
[44] https://attack.mitre.org/campaigns/C0022/
[46] https://www.researchgate.net/publication/374977618_Lazarus_campaigns_and_backdoors_in_2022-2023
[47] https://go.group-ib.com/report-lazarus-en
[48] https://www.fox-it.com/nl-en/how-the-lazarus-group-targets-fintech/
[49] https://go.group-ib.com/report-lazarus-en
[50] https://go.group-ib.com/report-lazarus-en
[51] https://blog.talosintelligence.com/lazarus-collectionrat/
[52] https://web-assets.esetstatic.com/wls/2020/06/ESET_Operation_Interception.pdf
[53] https://attack.mitre.org/software/S0181/
[57] https://securelist.com/operation-applejeus/87553/
[61] https://www.welivesecurity.com/2022/09/30/amazon-themed-campaigns-lazarus-netherlands-belgium/
[62] https://www.dia.mil/Portals/110/Documents/News/North_Korea_Military_Power.pdf
[63] https://www.dia.mil/Portals/110/Documents/News/North_Korea_Military_Power.pdf
[66] https://home.treasury.gov/news/press-releases/jy0768
[67] https://therecord.media/u-s-sanctions-tornado-cash-cryptocurrency-mixer
[68] https://www.bbc.com/news/business-61090064
