Threadlinqs IntelligenceStart free

Threat actorNorth KoreaTracked since 2026-02

Lazarus Group

Also known as:AndarielSilent ChollimaContagious InterviewContagious Interview - G1052APT 38APT-C-26APT38ATK117ATK3ApplewormBeagleBoyzBlack Artemis

As of 2026-10-08, Lazarus Group is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 29 threats spanning apt, supply chain, zero day. Also known as Andariel, Silent Chollima, Contagious Interview, Contagious Interview - G1052. ATT&CK coverage spans 214 techniques across 15 tactics in 29 of 29 tracked threats. Most-observed techniques: T1041 (Exfiltration Over C2 Channel), T1005 (Data from Local System), T1105 (Ingress Tool Transfer).

Tracked threats
2913 critical · 15 high · 1 medium
First seen
2026-02-12
Last seen
2026-09-25
ATT&CK techniques
214across 29 of 29 threats
Related CVEs
64Referenced by its activity
Attribution
North KoreaNation or origin
Nation: North Korea · 29 tracked threat(s) · Categories: APT, SUPPLY_CHAIN, ZERO_DAY, VULNERABILITY, MALWARE, RANSOMWARE, PHISHING

Activity timeline

Lazarus Group appears in 29 tracked threats between and ; the busiest month was 2026-07 with 6 reports.

ATT&CK techniques observed

214 techniques observed across 29 of 29 tracked threats · Stealth (formerly Defense Evasion) (43), Command and Control (20), Execution (20), Persistence (20), Credential Access (19), Resource Development (17)
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 22 of 29 tracked threats
  • T1005 Data from Local System — Collectionobserved in 21 of 29 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 21 of 29 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 20 of 29 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 19 of 29 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 14 of 29 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 14 of 29 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 14 of 29 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 14 of 29 tracked threats
  • T1204 User Execution — Executionobserved in 14 of 29 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 13 of 29 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 13 of 29 tracked threats
  • T1555 Credentials from Password Stores — Credential Accessobserved in 13 of 29 tracked threats
  • T1657 Financial Theft — Impactobserved in 13 of 29 tracked threats
  • T1566 Phishing — Initial Accessobserved in 11 of 29 tracked threats

Tracked threats

Related CVEs

40 of 64 CVEs referenced by tracked Lazarus Group activity