Lazarus Group is a public threat-intelligence label for North Korean state-linked cyber activity. Governments and security researchers have attributed operations under this name to the country’s Reconnaissance General Bureau, while reported objectives span espionage, financial theft, disruption, and strategic access. The label is imprecise: sources divide North Korean operators differently, and not every DPRK-linked intrusion is Lazarus Group activity. This guide explains the evidence, major campaigns, recurring behaviors, and defensive priorities without treating overlapping names as interchangeable.
Important attribution note. Threat-actor names are analytical labels, and different sources may split or combine the same activity. An alias can represent a government label, vendor cluster, subgroup, campaign, or public persona. The article therefore retains each source’s wording, date, and material caveats.