Threat actor · all actors
Fancy Lazarus (DDoS extortion persona)HACK-FANCY-LAZARUS hacktivist
aka Fancy Lazarus (DDoS extortion persona), Fancy Lazarus crew
Last updated: 2026-07-03
0attributed CVEs
0ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
—years active
About this actor
A 2020-2021 DDoS-extortion campaign whose operators alternated between impersonating Fancy Bear, Lazarus Group, and Armada Collective. Hacktivist-style messaging accompanied the extortion attempts targeting US and European financial institutions; Akamai and Radware reported widespread but largely unsuccessful shakedowns.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
No techniques attributed.
Co-occurring actors
None.
Similar actors
Same category
- Al-Toufan 1.00
- AnonOps 1.00
- Anonymous 1.00
- Anonymous Brasil 1.00
- Anonymous Collective 1.00