Adversary-emulation profile for Lazarus Group (G0032, aka Hidden Cobra / Diamond Sleet / Labyrinth Chollima), a North Korean RGB-linked actor conducting espionage, destructive, and financially motivated operations.
54
61%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/lazarus-group/SKILL.mdLazarus Group (MITRE ATT&CK G0032) is a North Korean state-sponsored threat actor active since at least 2009 and attributed by the U.S. Government and the security industry to the DPRK's Reconnaissance General Bureau (RGB). It is one of the most versatile and prolific nation-state actors observed, running three overlapping mission types in parallel: strategic espionage, destructive/disruptive attacks (e.g., the 2014 Sony Pictures wiper and the 2017 WannaCry outbreak), and large-scale financially motivated theft to fund the sanctioned regime (SWIFT bank fraud, ATM "FASTCash" cash-outs, and cryptocurrency heists). MITRE and vendors track several clusters/aliases under or alongside the Lazarus umbrella — HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet (Microsoft), and Labyrinth Chollima (CrowdStrike) — with financial sub-clusters often labeled APT38 / BlueNoroff / Stardust Chollima. The group blends bespoke malware, trojanized legitimate software, supply-chain compromise, and elaborate social engineering (fake recruiter "job offers") to reach hardened targets.
(Technique IDs verified against MITRE ATT&CK G0032.)
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
(IDs from MITRE ATT&CK Software associated with G0032; "custom" = DPRK-developed, "public" = commodity/open tool.)
Authorized use only. Execute these emulations exclusively inside the signed rules-of-engagement and scope of the current engagement. Never touch out-of-scope assets, never deploy genuinely destructive payloads against production, and use benign, instrumented stand-ins for any wiper/ransomware behavior.
Map Lazarus signature TTPs to Decepticon capabilities to reproduce the actor's behavior chain for the blue cell:
mshta/regsvr32/rundll32 proxy execution, WMI process creation, and new Scheduled Tasks/Services with masqueraded names (counters T1059, T1218, T1047, T1053.005, T1036.004).vssadmin/shadow-copy tampering, and unexpected service-stop or shutdown commands (counters T1485, T1561, T1489, T1529).4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.