The “Lazarus Effect” is a term used to describe the phenomena of cyber attacks carried out by the North Korean state-sponsored hacking group, known as Lazarus.
This group is notorious for its elaborate and sophisticated attacks on global financial institutions, governments, and private corporations.
History of Lazarus Group
The Lazarus group was first identified in 2014, following a cyber attack on Sony Pictures Entertainment. The attack resulted in the theft of confidential data, including unreleased films and employee personal information.
It was later revealed that North Korea was behind the attack, and the Lazarus group was identified as the primary actor.
Since the Sony attack, the group has carried out numerous attacks on various organizations and countries, targeting financial institutions with the aim of stealing money.
The group has also been linked to the WannaCry ransomware attack in 2017 that affected computers in over 150 countries, causing millions of dollars in damages.
Global Incidents of Lazarus Effect
Below are some of the notable global incidents of the “Lazarus Effect”:.
1. Bangladesh Bank Heist
In February 2016, the Lazarus group launched a cyber attack on the Bangladesh Bank, the central bank of Bangladesh. The attack resulted in the theft of over $81 million from the bank’s account at the Federal Reserve Bank of New York.
The group gained access to the bank’s system by exploiting vulnerabilities in the SWIFT messaging system, used by banks for financial transactions.
2. Sony Pictures Entertainment Hack
In November 2014, the Lazarus group launched a cyber attack on Sony Pictures Entertainment. The attack resulted in the theft of confidential data, including unreleased films and employee personal information.
It was later revealed that North Korea was behind the attack, and the Lazarus group was identified as the primary actor.
3. WannaCry Ransomware Attack
In May 2017, the Lazarus group launched a ransomware attack known as “WannaCry”. The attack affected computers in over 150 countries, causing millions of dollars in damages.
The ransomware encrypted files and demanded payment in exchange for the decryption key. The attack was a wake-up call for organizations to increase their cybersecurity efforts.
4. BlacKBerry Cylance Report
In 2018, security researchers at BlacKBerry Cylance released a report that revealed the Lazarus group had launched a series of attacks on cryptocurrency firms.
The report identified several attacks on exchanges and individual users, resulting in the theft of millions of dollars worth of cryptocurrencies.
5. South Korea Cyber Attack
In 2013, a series of cyber attacks targeted South Korean banks and broadcasters. The attacks were traced back to the Lazarus group, with the aim of disrupting the country’s financial system and causing panic among its residents.
6. TeslaCrypt Ransomware Attack
In 2015, the Lazarus group launched a ransomware attack known as TeslaCrypt. The attack encrypted files on victim’s computers and demanded payment in exchange for the decryption key.
This attack served as an example of the group’s evolving tactics towards ransomware.
7. North Korean Lazarus Group Suspected for COVID-themed Phishing Campaigns
In May 2020, there were reports that the Lazarus group may have been behind a series of phishing attacks exploiting the COVID-19 global pandemic.
The attacks aimed to target government officials, high-ranking military personnel, and pharmaceutical companies.
8. Lazarus Group Suspected of Attacking the COVID-19 Vaccine Supply Chain
In December 2020, the Lazarus group was accused of launching attacks on the COVID-19 vaccine supply chain in Europe.
The attacks targeted companies involved in the development and distribution of the vaccine, with the aim of stealing sensitive information.
9. SolarWinds Supply Chain Attack
In December 2020, the United States government announced that a supply chain attack had affected several government agencies and private corporations. The attack was traced back to a software update from SolarWinds, a leading IT infrastructure provider.
The attack was attributed to the Lazarus group and other state-sponsored hacking groups.
10. Attacks on Global Financial Institutions
The Lazarus group is known for its persistent attacks on global financial institutions. The group has been linked to attacks on banks in Poland, Mexico, and India, among others.
The attacks have resulted in numerous data breaches and thefts of millions of dollars.
Conclusion
The Lazarus group is a persistent and evolving threat to global cybersecurity. The group’s sophisticated attacks, ranging from ransomware to supply chain attacks, have caused millions of dollars in damages.
As the group continues to evolve, it is essential for organizations and governments to stay vigilant and increase their cybersecurity measures.