Validin will be at Black Hat 2026, Booth #6200 — schedule time to meet with us for an enterprise demo or an online meeting

Lazarus Group

Aliases: Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet • Lazarus Group is a North Korean state-sponsored threat group known for conducting high-profile attacks and cyber espionage campaigns. They have been active since at least 2009 and are linked to various destructive malware and operations.
Profile
Malicious
Category
Threat Actor Group
Threat Type
KP
Country
lazarus_group
Profile Key
The profile key is a unique identifier for this threat actor. It can be used to query the Validin APIs as the threat_key for information about this threat actor.
Last Updated
Summary
Indicator Activity
Loading activity...
No indicators recorded yet.
Description

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau. Active since at least 2009, they are known for various high-profile attacks, including the 2014 destructive wiper attack against Sony Pictures Entertainment. Their operations have also been linked to other campaigns like Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. It's important to note that there is significant overlap in North Korean group definitions, and some researchers attribute all North Korean state-sponsored cyber activity to Lazarus Group.

Aliases (6)
Labyrinth Chollima
Alias
HIDDEN COBRA
Alias
Guardians of Peace
Alias
ZINC
Alias
NICKEL ACADEMY
Alias
Diamond Sleet
Alias
Targets (2)
Various
Target
Sony Pictures Entertainment
Target
External Sources
Description References (1)
Reference