| Type | Company | [sources] | |||
|---|---|---|---|---|---|
| Name | Lazarus Group · ラザルス・グループ | [sources] | |||
| Alias | APT 38 · Andariel · Bluenoroff · Guardians of Peace · THE NEW ROMANTIC CYBER ARMY TEAM · | [sources] | |||
| Weak alias | APT-C-26 · Appleworm · Group 77 · Guardians of Peace · Hidden Cobra · | [sources] | |||
| Incorporation date | not available | [sources] | |||
| Jurisdiction | not available | [sources] | |||
| Country | North Korea | [sources] | |||
| Description | North Korean cybercrime group controlled by the Reconnaissance General Bureau (RGB; KPe.031). | [sources] | |||
| PermID | 5096757505 | [sources] | |||
| Registration number | not available | [sources] | |||
| Unique Entity ID | LQ4GFKZVYWN3 | [sources] | |||
| Status | Active | [sources] | |||
| Address | North Korea · POTONGGANG DISTRICT, PYONGYANG · Potonggang District Pyongyang Korea, North · Potonggang District, Pyongyang · Potonggang District, Pyongyang, Democratic People's Republic of Korea · | [sources] | |||
| Source link | home.treasury.gov · home.treasury.gov · home.treasury.gov · home.treasury.gov · home.treasury.gov · | [sources] | |||
| Last change | Last processed | First seen | |||
0x3e37627dEAA754090fBFbb8bd226c1CE66D255e9;
0x35fB6f6DB4fb05e6A4cE86f2C93691425626d4b1;
0x08723392Ed15743cc38513C4925f5e6be5c17243;
0x3Cffd56B47B7b41c56258D9C7731ABaDc360E073;
0xa0e1c89Ef1a489c9C7dE96311eD5Ce5D32c20E4B;
0x53b6936513e738f44FB50d2b9476730C0Ab3Bfc1;
0xF7B31119c2682c88d88D455dBb9d5932c65Cf1bE;
0x098B716B8Aaf21512996dC57EB0615e2383E2f96;
暗号資産アドレス:
ヒドゥン・コブラ;オフィス91;ガーディアンズ・オブ・ピース;ザ・ニュー・ロマンティック・サイバー・アーミー・チーム;フーイズ・ハッキング・チーム;レッド・ドット;テンプ・ハーミット;グループ77;ジンク;エー・ピー・ティー・シー26;アップルワーム
Hidden Cobra; Office 91; Guardians of Peace; The New Romantic Cyber Army Team; Whois Hacking Team; Red Dot; Temp.Hermit; Group 77; Zinc; APT-C-26; Appleworm
According to Footnote 110 (p. 50) of the UN Panel of Experts March 2019 report, Lab 110 could be the same organization as Lazarus Group: "The United States stated that Chosun Expo is “a front company affiliated with Lab 110, one of the North Korean government’s hacking organizations. That hacking group is what some private cybersecurity researchers have labeled the “Lazarus Group.”".
Cryptocurrency addresses connected to the $41 million theft from Stake.com, attributed to the Lazarus Group.
United States · FBI
Sanctions imposed by Japan under its Foreign Exchange and Foreign Trade Law.
Japan · MoF
The primary United States' sanctions list, specially designated nationals (SDN) part.
United States · OFAC
Entities subject to export restrictions due to concerns about the end-use or end-users, particularly relating to weapons of mass destruction (WMD) or other military applications.
Taiwan · MOEA
The Consolidated Screening List (CSL) is a list of parties for which the United States Government maintains restrictions on certain exports, re-exports, or transfers of items.
United States · ITA
A database of entities and events related to North Korea's sanctions evasion efforts.
United Kingdom · RUSI · non-official source
The Consolidated List is a list of all persons and entities who are subject to targeted financial sanctions under Australian sanctions law
Australia · DFAT
A database of suppliers who have been excluded from participating in US federal procurement.
United States · GSA
The record has been enriched with data from the following external databases:
US OFAC press releases that provide context and details related to sanctioned entities.
External dataset · United States · OFAC
Permanent Identifier (PermID) is a reference data spine offered by LSEG/Refinitiv to help create unique identifiers for organizations that are publicly listed.
External dataset · LSEG · non-official source
ofac-pr-4286698de4980b3df90331104fdc1d554fa8d1f6 · ofac-pr-1f06eead78534906b17e5141632f459afbdc2328 · au-dfat-8386-lazarus-group · ofac-27307 · tw-shtc-d6c693a662b39d408624b5140400462872ad5269 · ja-mof-adcae85e9ca37a3d3b0f199255441916c619e1df · usgsa-s4mr9rtm0 · ofac-pr-a2ae8e20bc1f1fef99cf3bec47c324172d51bf06 · permid-5096757505 · fbi-lazarus-lazarus-group · tw-shtc-cdcf6a89a482ce83526a49f4c4970d27c6f2e452 · kprusi-a4493abed7460d726f3b182da5cee1ce8be722ddFor experts: raw data explorer
OpenSanctions is free for non-commercial users. Businesses must acquire a data license to use the dataset.
| Address | ||
|---|---|---|
| Full address | Country | |
| Potonggang District, Pyongyang, Democratic People's Republic of Korea | - | |
| Cryptocurrency wallets | ||
|---|---|---|
| Currency | Address | |
| Ethereum | 0x7d84d78bb9b6044a45fa08b7fe109f2c8648ab4e | |
| Bitcoin | bc1qg0qygyv3qfp8cjyy99ch9vc9dp876vl8wys67u | |
| Documents | ||
|---|---|---|
| Document | Date | |
| Sanctions Imposed on DPRK IT Workers Generating Revenue for the Kim Regime | ||
| Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups | ||
| Linked from | ||||
|---|---|---|---|---|
| Subject | Role | Start date | End date | |
| Bluenoroff Debarred entity · Export controlled · Sanctioned entity | BlueNoroff (Stardust Chollima) is a subgroup of the Lazarus Group | - | - | |
| Japan | Ministry of Finance | 国際平和のための国際的な努力に我が国として寄与するために講ずる資産凍結等の措置の対象となる | - |
| Australia | Department of Foreign Affairs and Trade | Democratic People's Republic Of Korea (North Korea) Sanctions Regime | - |
| United States | Office of Foreign Assets Control | North Korea Sanctions | - | - |
| North Korea |
| 北朝鮮平壌特別市普通江区域 | - |
| Bitcoin | bc1qfesn3jj65fhmf00hh45ueql8je8jae6ep3qk84 |
| Bitcoin | bc1qqydp9muxtnxyet3ryfqc467wjtm23f0r7eh5aa |
| Bitcoin | bc1qqa682d2q0wtx5gfpxh4yfl9s4k00ukakl5fpk5 |
| Polygon | 0xa2e898180d0bc3713025d8590615a832397a8032 |
| BSC | 0x0004a76e39d33edfeac7fc3c8d3994f54428a0be |
| Bitcoin | bc1qtnuzecpqaakj0dt855n24dv7u5pme7vyct2cf2 |
| Bitcoin | bc1qqvpjgaurtnhc8smkmdtwhx9c8207m0prsyxyjx |
| Bitcoin | bc1qy0ggpxu8f6lta6vf44vervr4py2uu829grj8yh |
| Treasury Designates DPRK Weapons Representatives |
| Treasury Sanctions Individuals Laundering Cryptocurrency for Lazarus Group |
| U.S. Treasury Issues First-Ever Sanctions on a Virtual Currency Mixer, Targets DPRK Cyber Threats |
| Yinyin Tian Debarred entity · Export controlled · Sanctioned entity | Providing support to | - | - |
| JMT Trader | Linked | - | - |
| Celas Ltd. | Celas is a fake shell company backed by the Lazarus group | - | - |
| Kim Hyon Woo | Kim Hyon Woo is a fake persona used by the Lazarus Group | - | - |
| Reconnaissance General Bureau Debarred entity · Export controlled · Sanctioned entity | The Reconnaissance General Bureau oversees all North Korean cybercrime activities, Lazarus group included | - | - |
| UNC 4899 | The entities have "overlaps" | - | - |
| Jiadong Li Debarred entity · Export controlled · Sanctioned entity | Providing support to | - | - |
| Huihui Wu Debarred entity · Export controlled · Sanctioned entity | Providing support to | - | - |
| Third Bureau of the Reconnaissance General Bureau | The Lazarus Group is reported to be included in the Third Bureau of the Reconnaissance General Bureau | - | - |
| Andariel | Andariel is a subgroup of Lazarus | - | - | |
| 110 Research Institute of the Reconnaissance General Bureau | Larazus Group is working with or on behalf of the 110 Research Institute | - | - |
| Park Jin Hyok Debarred entity · Export controlled · Sanctioned entity | Member | - | - |