The four features of this adversary's intrusions under the Diamond Model — adversary, capability, infrastructure, victim — assembled from tracked data; pivot from any vertex to the others.
+180 more relationships — see the relationships browser.
Attribution ≠ confirmation. This view assembles Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff's intrusions from tracked data and primary reporting (40 archived reports, MITRE G0032) — individual vertex links are analytic, not each independently confirmed. Treat it as an assessment, not a settled fact.
The actor's techniques grouped into kill-chain phases — a partial order across phases; techniques within a phase are co-occurring, not sequenced. Export opens in CTID's Attack Flow Builder.
Phase groupings reflect ATT&CK tactic classification, not a confirmed operational timeline for Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff — see the competing-hypotheses breakdown for how confident this attribution really is.
See the analysis →These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.