North Korea's Lazarus Group Divided into Six Cyber Clusters

North Korea's Lazarus Group Divided into Six Cyber Clusters

First seen 7 Sep 2026, 11:20 UTC Infosecurity-Magazinewww.sekoia.com 60.0

Article Content

Browse articles
ThreatCluster

Recent analysis by Sekoia and Kudelski Security reveals that North Korea's Lazarus Group operates through six distinct cyber clusters, focusing on espionage, financial activities, and sanctions evasion. The clusters include TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima, each characterized by specific tactics and operations. The reorganization of these units complicates attribution and mapping of North Korea's cyber capabilities. Thousands of IT workers, operating under false identities, support these operations by generating revenue and gaining access to organizations. This network extends globally, leveraging front companies and educational institutions in regions like China, Russia, and Africa. The report highlights the dual mandate of these clusters, blending espionage with financial motives, particularly in cryptocurrency theft. The findings emphasize the ongoing threat posed by North Korean cyber operations, which are integral to the regime's survival strategy.

Key Points: • North Korea's Lazarus Group is now categorized into six distinct cyber clusters. • Thousands of IT workers under false identities support North Korea's cyber operations. • The clusters blend espionage and financial activities, complicating attribution efforts.

Ask AI about this cluster

Timeline

2026-09-07
Analysis of Lazarus Group published
Sekoia and Kudelski Security released a report categorizing North Korea's Lazarus Group into six cyber clusters.
Infosecurity-Magazine
2026-09-07
DPRK cyber capabilities overview
The analysis details how North Korea uses cyber operations for sanctions evasion and revenue generation.
www.sekoia.com