CASE DOSSIER
fugitive
U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)
Docket: 2:18-mj-01479 Court: U.S. District Court for the Central District of California Opened: 2018-06-08 Sector: Media and Entertainment, Financial Services, Healthcare
Key Facts
Status
FUGITIVE
Legal disposition
Loss Amount
$1.3 billion
Attempted to steal over $1.3 billion in cash and cryptocurrency, including the $81 million Bangladesh Bank heist and extensive WannaCry disruptions across NHS hospitals.
Techniques
6
Verified mappings
Defendants
1
Named in charges
- Legal Status: FUGITIVE in U.S. District Court for the Central District of California.
- Primary Target Sector: Media and Entertainment, Financial Services, Healthcare.
- Documented Financial Loss: $1.3 billion.
- 6 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.
Procedural & Incident Timeline
2018-06-08 indictment
Criminal complaint filed charging Park Jin Hyok with computer fraud and wire fraud conspiracies.
2018-09-06 sanction
Treasury sanctions Park Jin Hyok and front company Chosun Expo Joint Venture.
2021-02-17 indictment
Unsealing of superseding indictment adding co-conspirators Jon Chang Hyok and Kim Il.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Park Jin Hyok | Democratic People's Republic of Korea | fugitive | Pending | None | Lazarus Group computer programmer charged with WannaCry, Sony Pictures attack, and Bangladesh Bank heist. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1485 | Data Destruction Impact | "The Sony Pictures attack used the Destover wiper to destroy master boot records and overwrite hard drives, rendering thousands of workstations permanently inoperable." | Criminal Complaint ¶ 42, Page 27 | reviewed |
| T1486 | Data Encrypted for Impact Impact | "Park and his co-conspirators developed and distributed the WannaCry ransomware worm that infected over 230,000 computers across 150 nations within days." | Criminal Complaint ¶ 88, Page 61 | reviewed |
| T1021.002 | SMB / Windows Admin Shares Lateral Movement | "WannaCry automated its spread using the EternalBlue SMB exploit code to compromise unpatched Windows servers." | Criminal Complaint ¶ 92, Page 64 | reviewed |
| T1027 | Obfuscated Files or Information Defense Evasion | "Park and his co-conspirators heavily obfuscated WannaCry and Destover binaries with custom XOR encoders and commercial packers." | Criminal Complaint ¶ 63, Page 42 | reviewed |
| T1001.002 | Steganography Command and Control | "Lazarus malware disguised executable payloads inside benign PNG image files using steganographic pixel modification algorithms." | Criminal Complaint ¶ 74, Page 51 | reviewed |
| T1068 | Exploitation for Privilege Escalation Privilege Escalation | "WannaCry automated exploitation of kernel pool memory corruption via EternalBlue to execute ring 0 shellcode." | Criminal Complaint ¶ 94, Page 66 | reviewed |
View 1 Proposed / Unverified Mapping Candidates
T1566.002: Spearphishing Link Proposed by rule
"Spearphishing emails were sent to bank officials at Bangladesh Bank directing them to fake SWIFT messaging updates."
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo), No. 2:18-mj-01479 (U.S. District Court for the Central District of California 2018), https://cyberattackcaselibrary.pages.dev/cases/us-v-park-jin-hyok-lazarus/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-park-jin-hyok-lazarus" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>