Rare APT Collaboration Emerges Between Russia and North Korea
A new discovery from Gen Threat Labs indicates that Russia’s Gamaredon and North Korea’s Lazarus may be sharing operational infrastructure — a rare and concerning sign of cooperation between state- threat actors.
Early analysis shows activity from both threat actors on the same server within days, a convergence researchers describe as “too close to ignore.”
“These partnerships demonstrate a growing trend of resource sharing and tactical alignment within national ecosystems, amplifying the reach and resilience of state- campaigns,” researchers wrote in a blog post .
On July 28, 2025, Gen’s internal monitoring systems flagged a known Gamaredon command-and-control (C2) address — 144[.]172[.]112[.]106 — after detecting activity tied to the group’s Telegram and Telegraph-based infrastructure.
Four days later, the same IP began hosting an obfuscated variant of InvisibleFerret, a malware family attributed to Lazarus and previously deployed in its ContagiousInterview recruitment-themed campaign.
The server structure and delivery path (/payload/99/81) matched Lazarus’s known playbook.
While the IP could represent a proxy or VPN endpoint, researchers noted the close timing, identical delivery structure, and payload lineage as strong indicators of shared infrastructure.
No CVEs or public exploits are involved; rather, this case centers on infrastructure overlap and threat attribution patterns.
Gamaredon conducts espionage and disruption for Russia’s FSB, while Lazarus carries out espionage and financially motivated attacks for North Korea ’s Reconnaissance General Bureau (RGB).
Historically, APT groups from separate nation-states have not cooperated, with the last well-documented example being the joint US–UK Regin framework in 2014.
If validated, a Gamaredon–Lazarus collaboration would indicate:
The discovery builds on additional indicators of APT collaboration within national ecosystems:
These examples reinforce that APT collaborations — whether intentional or opportunistic — are becoming more common as states centralize cyber capabilities.
Even without confirmed joint operations, cross-actor infrastructure reuse presents major detection and attribution challenges.
To defend against emerging APT collaborations and shared infrastructure, security teams should take the following actions:
These measures reflect a broader movement toward anticipating hybrid threats that draw from multiple APT playbooks simultaneously.
Editor’s note: This article first appeared on our sister publication, eSecurityPlanet.com .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
