CSIDB logo
Threat actor

Lazarus Group

Attribution profile

Type
Nation State
Location
North Korea
Known incidents
2 incidents
First seen
2016-12-26
Last seen
2017-05-12
Updated
2026-08-01 05:31
Aliases
4 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actors behind the ZEE5 data breach have not been assigned a public alias in open‑source reporting and are referred to in coverage as the perpetrators of the ZEE5/Ott data leak. Their targeting focuses on media and entertainment organizations, specifically over‑the‑top platforms and satellite television services, with activity concentrated in India as evidenced by the compromise of Essel Group’s ZEE5 service and its sister Dish TV network. The actors’ motive, as characterized by ZEE5’s Head of Technology, is described as a shallow attempt to gain vested interests, indicating a financially or competitively driven aim rather than pure espionage. No public attribution to a state sponsor or known criminal syndicate has been made based on the available material.

The actors’ tactics, techniques and procedures highlighted in the source involve the exploitation of secrets embedded in live source code, which yielded AWS bucket credentials that were subsequently abused. They also left references to an internal Atlassian board—likely Jira or Confluence—and accessed a network drive labeled dish‑tv, indicating the misuse of misconfigured cloud storage and collaboration tools. Initial access appears to have stemmed from exposed credentials or inadequately protected development artifacts, as no specific malware families are mentioned in the reporting. Their approach relies on leveraging publicly available secrets and cloud misconfigurations to exfiltrate subscriber data such as transaction records, email addresses, mobile numbers and passwords.

Attribution remains unresolved; open‑source sources do not link this activity to any nation‑state group or established criminal consortium, and no formal ties to a government sponsor or organized cybercrime alliance have been established. Consequently, the threat cluster is treated as an unattributed set of actors whose actions are documented solely through the disclosed breach.

The most publicly documented operation attributed to this group is the 2021‑2022 ZEE5 data breach, during which they released a subset of the platform’s subscriber database containing recent transaction data, email addresses, mobile numbers and passwords. A screenshot shared by the actors displayed a dish‑tv network drive, underscoring that the compromise extended to the sister satellite TV service owned by the same Essel Group. ZEE5’s technology chief characterized the incident as a shallow attempt to gain vested interests, highlighting the growing interest of threat actors in India’s OTT sector after the COVID‑19 surge. This case illustrates the risks posed by exposed source‑code secrets and inadequately secured cloud assets within the media and entertainment sector.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB