| Type | Organization | [sources] | |||
|---|---|---|---|---|---|
| Name | Lazarus Group · ラザルス・グループ | [sources] | |||
| Alias | APT 38 · Andariel · Bluenoroff · Guardians of Peace · THE NEW ROMANTIC CYBER ARMY TEAM · | [sources] | |||
| Weak alias | APT-C-26 · Appleworm · Group 77 · Guardians of Peace · Hidden Cobra · | [sources] | |||
| Legal form | not available | [sources] | |||
| Country | North Korea | [sources] | |||
| Description | North Korean cybercrime group controlled by the Reconnaissance General Bureau (RGB; KPe.031). | [sources] | |||
| Unique Entity ID | LQ4GFKZVYWN3 | [sources] | |||
| Status | not available | [sources] | |||
| Address | POTONGGANG DISTRICT, PYONGYANG, PRK · Potonggang District Pyongyang Korea, North · Potonggang District, Pyongyang · Potonggang District, Pyongyang, Democratic People's Republic of Korea · 北朝鮮平壌特別市普通江区域 | [sources] | |||
| Source link | home.treasury.gov · home.treasury.gov · home.treasury.gov · home.treasury.gov · home.treasury.gov · | [sources] | |||
| Last change | Last processed | First seen | |||
0x3Cffd56B47B7b41c56258D9C7731ABaDc360E073;
暗号資産アドレス:
ヒドゥン・コブラ;オフィス91;ガーディアンズ・オブ・ピース;ザ・ニュー・ロマンティック・サイバー・アーミー・チーム;フーイズ・ハッキング・チーム;レッド・ドット;テンプ・ハーミット;グループ77;ジンク;エー・ピー・ティー・シー26;アップルワーム
Hidden Cobra; Office 91; Guardians of Peace; The New Romantic Cyber Army Team; Whois Hacking Team; Red Dot; Temp.Hermit; Group 77; Zinc; APT-C-26; Appleworm
0xF7B31119c2682c88d88D455dBb9d5932c65Cf1bE;
0x3e37627dEAA754090fBFbb8bd226c1CE66D255e9;
0x098B716B8Aaf21512996dC57EB0615e2383E2f96;
0xa0e1c89Ef1a489c9C7dE96311eD5Ce5D32c20E4B;
0x08723392Ed15743cc38513C4925f5e6be5c17243;
0x53b6936513e738f44FB50d2b9476730C0Ab3Bfc1;
0x35fB6f6DB4fb05e6A4cE86f2C93691425626d4b1;
According to Footnote 110 (p. 50) of the UN Panel of Experts March 2019 report, Lab 110 could be the same organization as Lazarus Group: "The United States stated that Chosun Expo is “a front company affiliated with Lab 110, one of the North Korean government’s hacking organizations. That hacking group is what some private cybersecurity researchers have labeled the “Lazarus Group.”".
The primary United States' sanctions list, specially designated nationals (SDN) part.
United States · OFAC
A database of suppliers who have been excluded from participating in US federal procurement.
United States · GSA
Cryptocurrency addresses connected to the $41 million theft from Stake.com, attributed to the Lazarus Group.
United States · FBI
The Consolidated Screening List (CSL) is a list of parties for which the United States Government maintains restrictions on certain exports, re-exports, or transfers of items.
United States · ITA
Sanctions imposed by Japan under its Foreign Exchange and Foreign Trade Law.
Japan · MoF
Entities subject to export restrictions due to concerns about the end-use or end-users, particularly relating to weapons of mass destruction (WMD) or other military applications.
Taiwan · MOEA
The Consolidated List is a list of all persons and entities who are subject to targeted financial sanctions under Australian sanctions law
Australia · DFAT
A database of entities and events related to North Korea's sanctions evasion efforts.
United Kingdom · RUSI · non-official source
The record has been enriched with data from the following external databases:
US OFAC press releases that provide context and details related to sanctioned entities.
External dataset · United States · OFAC
ofac-pr-1f06eead78534906b17e5141632f459afbdc2328 · tw-shtc-cdcf6a89a482ce83526a49f4c4970d27c6f2e452 · usgsa-s4mr9rtm0 · ofac-27307 · ofac-pr-a2ae8e20bc1f1fef99cf3bec47c324172d51bf06 · kprusi-a4493abed7460d726f3b182da5cee1ce8be722dd · fbi-lazarus-lazarus-group · au-dfat-8386-lazarus-group · ofac-pr-4286698de4980b3df90331104fdc1d554fa8d1f6 · tw-shtc-d6c693a662b39d408624b5140400462872ad5269 · ja-mof-adcae85e9ca37a3d3b0f199255441916c619e1dfFor experts: raw data explorer
OpenSanctions is free for non-commercial users. Businesses must acquire a data license to use the dataset.
| Address | ||
|---|---|---|
| Full address | Country | |
| Potonggang District, Pyongyang | North Korea | |
| 北朝鮮平壌特別市普通江区域 | - | |
| Cryptocurrency wallets | ||
|---|---|---|
| Currency | Address | |
| ETH | 0xF7B31119c2682c88d88D455dBb9d5932c65Cf1bE | |
| ETH | 0x08723392Ed15743cc38513C4925f5e6be5c17243 | |
| Documents | ||
|---|---|---|
| Document | Date | |
| Treasury Sanctions Individuals Laundering Cryptocurrency for Lazarus Group | ||
| U.S. Treasury Issues First-Ever Sanctions on a Virtual Currency Mixer, Targets DPRK Cyber Threats | ||
| Linked from | ||||
|---|---|---|---|---|
| Subject | Role | Start date | End date | |
| Yinyin Tian Export controlled · Sanctioned entity | Providing support to | - | - | |
| UNC 4899 | ||||
| Linked to | ||||
|---|---|---|---|---|
| Object | Role | Start date | End date | |
| 110 Research Institute of the Reconnaissance General Bureau | Larazus Group is working with or on behalf of the 110 Research Institute | - | - | |
| Andariel | ||||
| Japan | Ministry of Finance | 国際平和のための国際的な努力に我が国として寄与するために講ずる資産凍結等の措置の対象となる | - |
| United States | TREAS-OFAC | Reciprocal | - |
| United States | Office of Foreign Assets Control | North Korea Sanctions | - | - |
| Potonggang District, Pyongyang, Democratic People's Republic of Korea | - |
| BTC | 1c89Ef1a489c9C7dE96311eD5Ce5D32c2 |
| ETH | 0x35fB6f6DB4fb05e6A4cE86f2C93691425626d4b1 |
| ETH | 0x3Cffd56B47B7b41c56258D9C7731ABaDc360E073 |
| LTC | 31119c2682c88d88D455dBb9d5932c65Cf1bE |
| ETH | 0x098B716B8Aaf21512996dC57EB0615e2383E2f96 |
| ETH | 0x3e37627dEAA754090fBFbb8bd226c1CE66D255e9 |
| ETH | 0x53b6936513e738f44FB50d2b9476730C0Ab3Bfc1 |
| ETH | 0xa0e1c89Ef1a489c9C7dE96311eD5Ce5D32c20E4B |
| Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups |
| Treasury Designates DPRK Weapons Representatives |
| Sanctions Imposed on DPRK IT Workers Generating Revenue for the Kim Regime |
| - |
| - |
| JMT Trader | Linked | - | - |
| Bluenoroff Export controlled · Sanctioned entity | BlueNoroff (Stardust Chollima) is a subgroup of the Lazarus Group | - | - |
| Celas Ltd. | Celas is a fake shell company backed by the Lazarus group | - | - |
| Huihui Wu Export controlled · Sanctioned entity | Providing support to | - | - |
| Reconnaissance General Bureau Export controlled · Sanctioned entity | The Reconnaissance General Bureau oversees all North Korean cybercrime activities, Lazarus group included | - | - |
| Kim Hyon Woo | Kim Hyon Woo is a fake persona used by the Lazarus Group | - | - |
| Jiadong Li Export controlled · Sanctioned entity | Providing support to | - | - |
| Third Bureau of the Reconnaissance General Bureau | The Lazarus Group is reported to be included in the Third Bureau of the Reconnaissance General Bureau | - | - |
| Andariel is a subgroup of Lazarus |
| - |
| - |
| Park Jin Hyok Export controlled · Sanctioned entity | Member | - | - |