{
  "id": "case-lazarus-park-jin-hyok",
  "slug": "us-v-park-jin-hyok-lazarus",
  "title": "U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)",
  "summary": "Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.",
  "case_number": "2:18-mj-01479",
  "court": "U.S. District Court for the Central District of California",
  "district": "C.D. Cal.",
  "country": "United States",
  "opened_at": "2018-06-08",
  "status": "fugitive",
  "victim_sector": "Media and Entertainment, Financial Services, Healthcare",
  "victim_country": "United States, United Kingdom, Bangladesh, Philippines",
  "loss_amount_usd": 1300000000,
  "loss_amount_note": "Attempted to steal over $1.3 billion in cash and cryptocurrency, including the $81 million Bangladesh Bank heist and extensive WannaCry disruptions across NHS hospitals.",
  "first_seen_at": "2014-11-01T00:00:00Z",
  "last_updated_at": "2026-09-14T09:00:00Z",
  "actor_slug": "lazarus-group",
  "defendant_slugs": [
    "park-jin-hyok"
  ],
  "cves": [
    "CVE-2017-0144"
  ],
  "techniques": [
    {
      "technique_id": "T1485",
      "evidence_excerpt": "The Sony Pictures attack used the Destover wiper to destroy master boot records and overwrite hard drives, rendering thousands of workstations permanently inoperable.",
      "evidence_locator": "Criminal Complaint \u00b6 42, Page 27",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Data Destruction",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "Park and his co-conspirators developed and distributed the WannaCry ransomware worm that infected over 230,000 computers across 150 nations within days.",
      "evidence_locator": "Criminal Complaint \u00b6 88, Page 61",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1021.002",
      "evidence_excerpt": "WannaCry automated its spread using the EternalBlue SMB exploit code to compromise unpatched Windows servers.",
      "evidence_locator": "Criminal Complaint \u00b6 92, Page 64",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "SMB / Windows Admin Shares",
      "tactic": "Lateral Movement"
    },
    {
      "technique_id": "T1566.002",
      "evidence_excerpt": "Spearphishing emails were sent to bank officials at Bangladesh Bank directing them to fake SWIFT messaging updates.",
      "evidence_locator": "Complaint \u00b6 55",
      "mapping_status": "proposed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Spearphishing Link",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1027",
      "evidence_excerpt": "Park and his co-conspirators heavily obfuscated WannaCry and Destover binaries with custom XOR encoders and commercial packers.",
      "evidence_locator": "Criminal Complaint \u00b6 63, Page 42",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Obfuscated Files or Information",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1001.002",
      "evidence_excerpt": "Lazarus malware disguised executable payloads inside benign PNG image files using steganographic pixel modification algorithms.",
      "evidence_locator": "Criminal Complaint \u00b6 74, Page 51",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Steganography",
      "tactic": "Command and Control"
    },
    {
      "technique_id": "T1068",
      "evidence_excerpt": "WannaCry automated exploitation of kernel pool memory corruption via EternalBlue to execute ring 0 shellcode.",
      "evidence_locator": "Criminal Complaint \u00b6 94, Page 66",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Exploitation for Privilege Escalation",
      "tactic": "Privilege Escalation"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2018-06-08",
      "description": "Criminal complaint filed charging Park Jin Hyok with computer fraud and wire fraud conspiracies."
    },
    {
      "event_type": "sanction",
      "event_date": "2018-09-06",
      "description": "Treasury sanctions Park Jin Hyok and front company Chosun Expo Joint Venture."
    },
    {
      "event_type": "indictment",
      "event_date": "2021-02-17",
      "description": "Unsealing of superseding indictment adding co-conspirators Jon Chang Hyok and Kim Il."
    }
  ]
}