| Type | Company | [sources] | |||
|---|---|---|---|---|---|
| Name | Lazarus Group · ラザルス・グループ | [sources] | |||
| Alias | APT 38 · Andariel · Bluenoroff · Guardians of Peace · THE NEW ROMANTIC CYBER ARMY TEAM · | [sources] | |||
| Weak alias | APT-C-26 · Appleworm · Group 77 · Guardians of Peace · Hidden Cobra · | [sources] | |||
| Incorporation date | not available | [sources] | |||
| Jurisdiction | not available | [sources] | |||
| Country | North Korea | [sources] | |||
| Description | North Korean cybercrime group controlled by the Reconnaissance General Bureau (RGB; KPe.031). | [sources] | |||
| PermID | 5096757505 | [sources] | |||
| Registration number | not available | [sources] | |||
| Unique Entity ID | LQ4GFKZVYWN3 | [sources] | |||
| Status | Active | [sources] | |||
| Address | North Korea · POTONGGANG DISTRICT, PYONGYANG · Potonggang District Pyongyang Korea, North · Potonggang District, Pyongyang · Potonggang District, Pyongyang, Democratic People's Republic of Korea · | [sources] | |||
| Source link | home.treasury.gov · home.treasury.gov · home.treasury.gov · home.treasury.gov · home.treasury.gov · | [sources] | |||
| Last change | Last processed | First seen | |||
0x3e37627dEAA754090fBFbb8bd226c1CE66D255e9;
0x35fB6f6DB4fb05e6A4cE86f2C93691425626d4b1;
0x08723392Ed15743cc38513C4925f5e6be5c17243;
0x3Cffd56B47B7b41c56258D9C7731ABaDc360E073;
0xa0e1c89Ef1a489c9C7dE96311eD5Ce5D32c20E4B;
0x53b6936513e738f44FB50d2b9476730C0Ab3Bfc1;
0xF7B31119c2682c88d88D455dBb9d5932c65Cf1bE;
0x098B716B8Aaf21512996dC57EB0615e2383E2f96;
暗号資産アドレス:
ヒドゥン・コブラ;オフィス91;ガーディアンズ・オブ・ピース;ザ・ニュー・ロマンティック・サイバー・アーミー・チーム;フーイズ・ハッキング・チーム;レッド・ドット;テンプ・ハーミット;グループ77;ジンク;エー・ピー・ティー・シー26;アップルワーム
Hidden Cobra; Office 91; Guardians of Peace; The New Romantic Cyber Army Team; Whois Hacking Team; Red Dot; Temp.Hermit; Group 77; Zinc; APT-C-26; Appleworm
According to Footnote 110 (p. 50) of the UN Panel of Experts March 2019 report, Lab 110 could be the same organization as Lazarus Group: "The United States stated that Chosun Expo is “a front company affiliated with Lab 110, one of the North Korean government’s hacking organizations. That hacking group is what some private cybersecurity researchers have labeled the “Lazarus Group.”".
The Consolidated List is a list of all persons and entities who are subject to targeted financial sanctions under Australian sanctions law
Australia · DFAT
A database of entities and events related to North Korea's sanctions evasion efforts.
United Kingdom · RUSI · non-official source
Sanctions imposed by Japan under its Foreign Exchange and Foreign Trade Law.
Japan · MoF
Entities subject to export restrictions due to concerns about the end-use or end-users, particularly relating to weapons of mass destruction (WMD) or other military applications.
Taiwan · MOEA
A database of suppliers who have been excluded from participating in US federal procurement.
United States · GSA
The Consolidated Screening List (CSL) is a list of parties for which the United States Government maintains restrictions on certain exports, re-exports, or transfers of items.
United States · ITA
Cryptocurrency addresses connected to the $41 million theft from Stake.com, attributed to the Lazarus Group.
United States · FBI
The primary United States' sanctions list, specially designated nationals (SDN) part.
United States · OFAC
The record has been enriched with data from the following external databases:
Permanent Identifier (PermID) is a reference data spine offered by LSEG/Refinitiv to help create unique identifiers for organizations that are publicly listed.
External dataset · LSEG · non-official source
US OFAC press releases that provide context and details related to sanctioned entities.
External dataset · United States · OFAC
ofac-pr-a2ae8e20bc1f1fef99cf3bec47c324172d51bf06 · permid-5096757505 · ofac-pr-1f06eead78534906b17e5141632f459afbdc2328 · tw-shtc-d6c693a662b39d408624b5140400462872ad5269 · tw-shtc-cdcf6a89a482ce83526a49f4c4970d27c6f2e452 · ja-mof-adcae85e9ca37a3d3b0f199255441916c619e1df · ofac-27307 · ofac-pr-4286698de4980b3df90331104fdc1d554fa8d1f6 · kprusi-a4493abed7460d726f3b182da5cee1ce8be722dd · au-dfat-8386-lazarus-group · fbi-lazarus-lazarus-group · usgsa-s4mr9rtm0For experts: raw data explorer
OpenSanctions is free for non-commercial users. Businesses must acquire a data license to use the dataset.
| Address | ||
|---|---|---|
| Full address | Country | |
| Potonggang District, Pyongyang, Democratic People's Republic of Korea | - | |
| Cryptocurrency wallets | ||
|---|---|---|
| Currency | Address | |
| BSC | 0x0004a76e39d33edfeac7fc3c8d3994f54428a0be | |
| Bitcoin | bc1qg0qygyv3qfp8cjyy99ch9vc9dp876vl8wys67u | |
| Documents | ||
|---|---|---|
| Document | Date | |
| Treasury Sanctions Individuals Laundering Cryptocurrency for Lazarus Group | ||
| U.S. Treasury Issues First-Ever Sanctions on a Virtual Currency Mixer, Targets DPRK Cyber Threats | ||
| Linked from | ||||
|---|---|---|---|---|
| Subject | Role | Start date | End date | |
| Huihui Wu Debarred entity · Export controlled · Sanctioned entity | Providing support to | - | - | |
| United States | TREAS-OFAC | Reciprocal | - |
| United States | Office of Foreign Assets Control | North Korea Sanctions | - | - |
| Australia | Department of Foreign Affairs and Trade | Democratic People's Republic Of Korea (North Korea) Sanctions Regime | - |
| North Korea |
| 北朝鮮平壌特別市普通江区域 | - |
| Polygon | 0xa2e898180d0bc3713025d8590615a832397a8032 |
| Bitcoin | bc1qqa682d2q0wtx5gfpxh4yfl9s4k00ukakl5fpk5 |
| Bitcoin | bc1qqydp9muxtnxyet3ryfqc467wjtm23f0r7eh5aa |
| Bitcoin | bc1qtnuzecpqaakj0dt855n24dv7u5pme7vyct2cf2 |
| Ethereum | 0x7d84d78bb9b6044a45fa08b7fe109f2c8648ab4e |
| Bitcoin | bc1qfesn3jj65fhmf00hh45ueql8je8jae6ep3qk84 |
| Bitcoin | bc1qqvpjgaurtnhc8smkmdtwhx9c8207m0prsyxyjx |
| Bitcoin | bc1qy0ggpxu8f6lta6vf44vervr4py2uu829grj8yh |
| Sanctions Imposed on DPRK IT Workers Generating Revenue for the Kim Regime |
| Treasury Designates DPRK Weapons Representatives |
| Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups |
| Third Bureau of the Reconnaissance General Bureau | The Lazarus Group is reported to be included in the Third Bureau of the Reconnaissance General Bureau | - | - |
| UNC 4899 | The entities have "overlaps" | - | - |
| Reconnaissance General Bureau Debarred entity · Export controlled · Sanctioned entity | The Reconnaissance General Bureau oversees all North Korean cybercrime activities, Lazarus group included | - | - |
| Celas Ltd. | Celas is a fake shell company backed by the Lazarus group | - | - |
| Yinyin Tian Debarred entity · Export controlled · Sanctioned entity | Providing support to | - | - |
| JMT Trader | Linked | - | - |
| Kim Hyon Woo | Kim Hyon Woo is a fake persona used by the Lazarus Group | - | - |
| Bluenoroff Debarred entity · Export controlled · Sanctioned entity | BlueNoroff (Stardust Chollima) is a subgroup of the Lazarus Group | - | - |
| Jiadong Li Debarred entity · Export controlled · Sanctioned entity | Providing support to | - | - |
| 110 Research Institute of the Reconnaissance General Bureau | Larazus Group is working with or on behalf of the 110 Research Institute | - | - | |
| Andariel | Andariel is a subgroup of Lazarus | - | - |
| Park Jin Hyok Debarred entity · Export controlled · Sanctioned entity | Member | - | - |