CASE DOSSIER fugitive

U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)

Docket: 2:18-mj-01479 Court: U.S. District Court for the Central District of California Opened: 2018-06-08 Sector: Media and Entertainment, Financial Services, Healthcare

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$1.3 billion
Attempted to steal over $1.3 billion in cash and cryptocurrency, including the $81 million Bangladesh Bank heist and extensive WannaCry disruptions across NHS hospitals.
Techniques
6
Verified mappings
Defendants
1
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Central District of California.
  • Primary Target Sector: Media and Entertainment, Financial Services, Healthcare.
  • Documented Financial Loss: $1.3 billion.
  • 6 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.

Procedural & Incident Timeline

2018-06-08 indictment

Criminal complaint filed charging Park Jin Hyok with computer fraud and wire fraud conspiracies.

2018-09-06 sanction

Treasury sanctions Park Jin Hyok and front company Chosun Expo Joint Venture.

2021-02-17 indictment

Unsealing of superseding indictment adding co-conspirators Jon Chang Hyok and Kim Il.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Park Jin Hyok Democratic People's Republic of Korea fugitive Pending None Lazarus Group computer programmer charged with WannaCry, Sony Pictures attack, and Bangladesh Bank heist.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1485 Data Destruction
Impact
"The Sony Pictures attack used the Destover wiper to destroy master boot records and overwrite hard drives, rendering thousands of workstations permanently inoperable." Criminal Complaint ¶ 42, Page 27 reviewed
T1486 Data Encrypted for Impact
Impact
"Park and his co-conspirators developed and distributed the WannaCry ransomware worm that infected over 230,000 computers across 150 nations within days." Criminal Complaint ¶ 88, Page 61 reviewed
T1021.002 SMB / Windows Admin Shares
Lateral Movement
"WannaCry automated its spread using the EternalBlue SMB exploit code to compromise unpatched Windows servers." Criminal Complaint ¶ 92, Page 64 reviewed
T1027 Obfuscated Files or Information
Defense Evasion
"Park and his co-conspirators heavily obfuscated WannaCry and Destover binaries with custom XOR encoders and commercial packers." Criminal Complaint ¶ 63, Page 42 reviewed
T1001.002 Steganography
Command and Control
"Lazarus malware disguised executable payloads inside benign PNG image files using steganographic pixel modification algorithms." Criminal Complaint ¶ 74, Page 51 reviewed
T1068 Exploitation for Privilege Escalation
Privilege Escalation
"WannaCry automated exploitation of kernel pool memory corruption via EternalBlue to execute ring 0 shellcode." Criminal Complaint ¶ 94, Page 66 reviewed
View 1 Proposed / Unverified Mapping Candidates
T1566.002: Spearphishing Link Proposed by rule

"Spearphishing emails were sent to bank officials at Bangladesh Bank directing them to fake SWIFT messaging updates."

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo), No. 2:18-mj-01479 (U.S. District Court for the Central District of California 2018), https://cyberattackcaselibrary.pages.dev/cases/us-v-park-jin-hyok-lazarus/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-park-jin-hyok-lazarus" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>