| Type | Organization | [sources] | |||
|---|---|---|---|---|---|
| Name | Lazarus Group · ラザルス・グループ | [sources] | |||
| Other name | APT 38 · Andariel · Bluenoroff · Guardians of Peace · THE NEW ROMANTIC CYBER ARMY TEAM · | [sources] | |||
| Weak alias | APT-C-26 · Appleworm · Group 77 · Guardians of Peace · Hidden Cobra · | [sources] | |||
| Legal form | not available | [sources] | |||
| Country | North Korea | [sources] | |||
| Description | North Korean cybercrime group controlled by the Reconnaissance General Bureau (RGB; KPe.031). | [sources] | |||
| Unique Entity ID | LQ4GFKZVYWN3 | [sources] | |||
| Status | not available | [sources] | |||
| Address | POTONGGANG DISTRICT, PYONGYANG, PRK · Potonggang District Pyongyang Korea, North · Potonggang District, Pyongyang · Potonggang District, Pyongyang, North Korea · 北朝鮮平壌特別市普通江区域 | [sources] | |||
| Source link | home.treasury.gov · home.treasury.gov · home.treasury.gov · home.treasury.gov · home.treasury.gov · | [sources] | |||
| Last change | Last processed | First seen | |||
Hidden Cobra; Office 91; Guardians of Peace; The New Romantic Cyber Army Team; Whois Hacking Team; Red Dot; Temp.Hermit; Group 77; Zinc; APT-C-26; Appleworm
0x35fB6f6DB4fb05e6A4cE86f2C93691425626d4b1;
0x08723392Ed15743cc38513C4925f5e6be5c17243;
0xa0e1c89Ef1a489c9C7dE96311eD5Ce5D32c20E4B;
ヒドゥン・コブラ;オフィス91;ガーディアンズ・オブ・ピース;ザ・ニュー・ロマンティック・サイバー・アーミー・チーム;フーイズ・ハッキング・チーム;レッド・ドット;テンプ・ハーミット;グループ77;ジンク;エー・ピー・ティー・シー26;アップルワーム
0x3Cffd56B47B7b41c56258D9C7731ABaDc360E073;
0x098B716B8Aaf21512996dC57EB0615e2383E2f96;
0xF7B31119c2682c88d88D455dBb9d5932c65Cf1bE;
暗号資産アドレス:
0x3e37627dEAA754090fBFbb8bd226c1CE66D255e9;
0x53b6936513e738f44FB50d2b9476730C0Ab3Bfc1;
According to Footnote 110 (p. 50) of the UN Panel of Experts March 2019 report, Lab 110 could be the same organization as Lazarus Group: "The United States stated that Chosun Expo is “a front company affiliated with Lab 110, one of the North Korean government’s hacking organizations. That hacking group is what some private cybersecurity researchers have labeled the “Lazarus Group.”".
A database of entities and events related to North Korea's sanctions evasion efforts.
United Kingdom · RUSI · non-official source
The Consolidated List is a list of all persons and entities who are subject to targeted financial sanctions under Australian sanctions law
Australia · DFAT
The Consolidated Screening List (CSL) is a list of parties for which the United States Government maintains restrictions on certain exports, re-exports, or transfers of items.
United States · ITA
Cryptocurrency addresses connected to the $41 million theft from Stake.com, attributed to the Lazarus Group.
United States · FBI
The primary United States' sanctions list, specially designated nationals (SDN) part.
United States · OFAC
Entities subject to export restrictions due to concerns about the end-use or end-users, particularly relating to weapons of mass destruction (WMD) or other military applications.
Taiwan · MOEA
A database of suppliers who have been excluded from participating in US federal procurement.
United States · GSA
Sanctions imposed by Japan under its Foreign Exchange and Foreign Trade Law.
Japan · MoF
The record has been enriched with data from the following external databases:
US OFAC press releases that provide context and details related to sanctioned entities.
External dataset · United States · OFAC
fbi-lazarus-lazarus-group · ofac-pr-e075e64920344708e41728ad462edc62c177c989 · au-dfat-8386-lazarus-group · kprusi-a4493abed7460d726f3b182da5cee1ce8be722dd · ofac-pr-a2ae8e20bc1f1fef99cf3bec47c324172d51bf06 · ofac-pr-4286698de4980b3df90331104fdc1d554fa8d1f6 · tw-shtc-cdcf6a89a482ce83526a49f4c4970d27c6f2e452 · ofac-pr-1f06eead78534906b17e5141632f459afbdc2328 · ja-mof-adcae85e9ca37a3d3b0f199255441916c619e1df · usgsa-s4mr9rtm0 · tw-shtc-d6c693a662b39d408624b5140400462872ad5269 · ofac-27307For experts: raw data explorer
OpenSanctions is free for non-commercial users. Businesses must acquire a data license to use the dataset.
| Address | ||
|---|---|---|
| Full address | Country | |
| Potonggang District, Pyongyang, North Korea | - | |
| Potonggang District, Pyongyang | North Korea | |
| Cryptocurrency wallets | ||
|---|---|---|
| Currency | Address | |
| ETH | 0xF7B31119c2682c88d88D455dBb9d5932c65Cf1bE | |
| ETH | 0x35fB6f6DB4fb05e6A4cE86f2C93691425626d4b1 | |
| Documents | ||
|---|---|---|
| Document | Date | |
| Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups | ||
| Sanctions Imposed on DPRK IT Workers Generating Revenue for the Kim Regime | ||
| Linked from | ||||
|---|---|---|---|---|
| Subject | Role | Start date | End date | |
| Kim Hyon Woo | Kim Hyon Woo is a fake persona used by the Lazarus Group | - | - | |
| Jiadong Li Export controlled · | ||||
| Linked to | ||||
|---|---|---|---|---|
| Object | Role | Start date | End date | |
| Andariel | Andariel is a subgroup of Lazarus | - | - | |
| 110 Research Institute of the Reconnaissance General Bureau | Larazus Group is working with or on behalf of the 110 Research Institute | |||
| Australia | Department of Foreign Affairs and Trade | Democratic People's Republic Of Korea (North Korea) Sanctions Regime | - |
| Japan | Ministry of Finance | 国際平和のための国際的な努力に我が国として寄与するために講ずる資産凍結等の措置の対象となる | - |
| United States | TREAS-OFAC | Reciprocal | - |
| 北朝鮮平壌特別市普通江区域 | - |
| ETH | 0x098B716B8Aaf21512996dC57EB0615e2383E2f96 |
| ETH | 0x53b6936513e738f44FB50d2b9476730C0Ab3Bfc1 |
| ETH | 0x08723392Ed15743cc38513C4925f5e6be5c17243 |
| ETH | 0xa0e1c89Ef1a489c9C7dE96311eD5Ce5D32c20E4B |
| Bitcoin | bc1qy0ggpxu8f6lta6vf44vervr4py2uu829grj8yh |
| Bitcoin | bc1qqvpjgaurtnhc8smkmdtwhx9c8207m0prsyxyjx |
| ETH | 0x3Cffd56B47B7b41c56258D9C7731ABaDc360E073 |
| ETH | 0x3e37627dEAA754090fBFbb8bd226c1CE66D255e9 |
| U.S. Treasury Issues First-Ever Sanctions on a Virtual Currency Mixer, Targets DPRK Cyber Threats |
| Treasury Sanctions Individuals Laundering Cryptocurrency for Lazarus Group |
| Treasury Designates DPRK Weapons Representatives |
| Treasury Designates Roman Semenov, Co-Founder of Sanctioned Virtual Currency Mixer Tornado Cash |
| Treasury Sanctions Mixer Used by the DPRK to Launder Stolen Virtual Currency |
| Providing support to |
| - |
| - |
| Yinyin Tian Export controlled · Sanctioned entity | Providing support to | - | - |
| Reconnaissance General Bureau Export controlled · Sanctioned entity | The Reconnaissance General Bureau oversees all North Korean cybercrime activities, Lazarus group included | - | - |
| Celas Ltd. | Celas is a fake shell company backed by the Lazarus group | - | - |
| JMT Trader | Linked | - | - |
| Huihui Wu Export controlled · Sanctioned entity | Providing support to | - | - |
| Bluenoroff Export controlled · Sanctioned entity | BlueNoroff (Stardust Chollima) is a subgroup of the Lazarus Group | - | - |
| Third Bureau of the Reconnaissance General Bureau | The Lazarus Group is reported to be included in the Third Bureau of the Reconnaissance General Bureau | - | - |
| UNC 4899 | The entities have "overlaps" | - | - |
| - |
| - |
| Park Jin Hyok Export controlled · Sanctioned entity | Member | - | - |