Threat Intelligence / Actor / Lazarus Group

Lazarus Group

As of 2026-08-25, Lazarus Group is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 26 threats spanning vulnerability, malware, apt. Also known as andariel, appleworm, apt 38, apt-c-26.

Nation: North Korea (DPRK) · 26 tracked threat(s) · Categories: VULNERABILITY, MALWARE, APT, SUPPLY_CHAIN, RANSOMWARE, PHISHING

Also known as: Lazarus Group, andariel, appleworm, apt 38, apt-c-26, apt38, atk117, atk3, beagleboyz, black artemis, bluenoroff, bureau 121

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence