Back Infosecurity-Magazine North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
North Korea's Lazarus umbrella operates as six distinct cyber clusters, according to a new analysis of the country's offensive cyber capabilities.
Sekoia and Kudelski Security said the organization reflected a broader effort by North Korea to distribute cyber operations across units focused on espionage, financial activity and sanctions evasion.
The research , published on September 7, categorized the former Lazarus umbrella into TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima.
Lazarus Umbrella Divided Into Six Clusters
The researchers said North Korean cyber units had been repeatedly reorganized and renamed, complicating attribution and making the country's cyber structure difficult to map. Most of the threat actors examined sit under the GRIB, North Korea's main military intelligence bureau, formerly known as the RGB.
Sekoia and Kudelski Security said their latest clustering was based on tactics, techniques and procedures (TTPs) and the types of operations conducted by each group. Famous Chollima was distinguished by activity linked to fake IT workers, which the researchers said often supported the objectives of other cyber units.
Among the six, Moonstone Sleet combined cyberespionage with financially motivated operations, using its own custom malware alongside the Qilin ransomware-as-a-service (RaaS) platform. The researchers said a separate DPRK-nexus cluster, Andariel, followed a similar dual-mandate pattern.
The researchers also said the former APT38 cluster had likely split into CryptoCore and Jade Sleet, which they said were now focused on financial campaigns targeting cryptocurrency, Web3 and blockchain organizations.
IT Workers Extend the Cyber Operation
Alongside the APT clusters, North Korea's cyber capability included thousands of IT workers operating under false identities, according to the report.
Sekoia and Kudelski Security said these workers generated revenue for the regime while gaining access to organizations through legitimate employment. In some cases, workers queried internal corporate documentation or used access obtained through remote consulting roles to conduct further activity.
The report separately linked fake IT workers to direct cryptocurrency theft, including a $62.5m exploit of the Munchables protocol. It added that the IT worker program served both financial and operational purposes. Salaries were remitted to North Korea to help circumvent sanctions, while access obtained through employment could also support financial theft or espionage.
The wider ecosystem included front companies, educational institutions and third-country infrastructure in places including China, Russia, Southeast Asia and Africa. These networks provided operational cover, access and mechanisms for moving illicit funds.
Sekoia and Kudelski Security said the distinction between espionage and revenue generation is less firm than it appears.
Lazarus Group Attack Identified After Operational Security Fail News 2 February 2023
Lazarus Group Attack Identified After Operational Security Fail
New BeaverTail Malware Variant Linked to Lazarus Group News 18 December 2025
New BeaverTail Malware Variant Linked to Lazarus Group
Lazarus Group Targets MacOS Users Seeking Crypto Jobs News 27 September 2022
Lazarus Group Targets MacOS Users Seeking Crypto Jobs
North Korean Lazarus Group Hacked Energy Providers Worldwide News 12 September 2022
North Korean Lazarus Group Hacked Energy Providers Worldwide
ClickFake Interview Campaign by Lazarus Targets Crypto Job Seekers News 31 March 2025
ClickFake Interview Campaign by Lazarus Targets Crypto Job Seekers
What’s Hot on Infosecurity Magazine?
FBI Probes Possible Breach of 153 Million Driver’s Licenses
US and Canadian Court Records Breached Following Thomson Reuters Incident
Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
65% of Enterprises Have Seen AI Agents Act Out of Scope
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
Attackers Steal METR API Key and Burn $600,000 in AI Credits
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
Hiring for the AI Era: A New Challenge for CISOs
How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era
65% of Enterprises Have Seen AI Agents Act Out of Scope
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Predicting and Prioritizing Cyber Attacks Using Threat Intelligence
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
