Official ATT&CK groups · sourced comparison
Documented group behavior. Independent vehicle evidence.
Select a known ATT&CK group to inspect its sourced behavior path. A vehicle path appears only when accepted SBOM and canary records bind to that VIN.
Lazarus Group
Also tracked as Diamond Sleet · Guardians of Peace · HIDDEN COBRA · Labyrinth Chollima · NICKEL ACADEMY · ZINC
[Lazarus Group](https://attack.mitre.org/groups/G0032) is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber Groups September 2019) [Lazarus Group](https://attack.mitre.org/groups/G0032) has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by [Lazarus Group](https://attack.mitre.org/groups/G0032) correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.(Citation: Novetta Blockbuster) North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.(Citation: Mandiant DPRK Laz Org Breakdown 2022)(Citation: Mandiant DPRK Groups 2023)(Citation: JPCert Blog Laz Subgroups 2025)
Attribution boundary
Public ATT&CK identity and procedure records only. No relationship to Northstar, a customer, supplier, or selected VIN is asserted.
Official identity source
MITRE ATT&CK · G0032- ATT&CK record
- G0032
- Record version
- 5.0
- Created
- Unknown
- Last modified
- Unknown
- Catalogue release
- 19.2
- Replay fixture
- AL-BUILD-TRUST-1.1.0
- Technique overlaps
- 03
- Mapped events
- 05
- Evidence gates
- 13
- Defensive analytics
- 02
Operational sequence assessment
The active MITRE ATT&CK Enterprise release maps Lazarus Group to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.
Public behavior is a comparison lens · Northstar events below are synthetic · no attribution
Synthetic replay lane · not VIN evidence
Reached and failed counts below evaluate only the fixed Northstar fixture. They cannot open a vehicle path or establish group presence.
NO VIN
Independent VIN gates
Reached
0/3
Failed gates
0/3
Pending
3/3
Coverage gaps
0/3
- 1
- 2
- 3
Select a VIN to build this group’s full evidence path.
A VIN supplies the scope for SBOM, release-manifest and canary evidence. Group behavior remains a separate comparison lens.
Select VINExact ATT&CK joins
Public behavior mapped to fixture observations
Technique context retained
T1070.004 is highlighted below. Public group behavior remains separate from synthetic replay evidence.
PATH 01
T1070.004
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps Lazarus Group to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E14 to E28
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E1413:00Build interpositionFile integrity
Workspace restored to the committed state
The fixture is removed and the workspace again matches the commit. Post-build inspection of the workspace now shows nothing — the window has closed.
BLD-WIN-03
- E1615:00Build interpositionFile integrity
Short-lived file mutation recorded, not alerted
File-integrity monitoring recorded create and delete inside the workspace but the workspace path is excluded from alerting. The evidence existed; the rule did not.
BLD-WIN-03
- E2824:30InvestigationFile integrity
Transient workspace mutation recovered from raw records
The create/delete pair is still in the raw file-integrity stream even though no alert fired. Retention, not alerting, saved this investigation.
BLD-WIN-03
PATH 02
T1071.001
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps Lazarus Group to T1071.001 Application Layer Protocol: Web Protocols. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E23 to E23
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E2322:00Downstream signalEgress proxy
Egress proxy records a first-seen destination from the build tier
One request to updates.example.net (TEST-NET-2 198.51.100.24) from a host whose baseline destination list contains four entries. First-seen egress from build infrastructure is unusually cheap to detect.
BLD-WIN-03
PATH 03
T1591
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps Lazarus Group to T1591 Gather Victim Org Information. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E02 to E02
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0201:00ReconnaissanceEgress proxy
Reconnaissance — reasoning about the environment, no intrusion
The emulated adversary reads the vendor's public technology inventory. No intrusion step is modelled or described.