ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

mediumThreat actorimportance 75
AI summary · glm-5.3-flash

Sekoia and Kudelski Security reclassify North Korea's Lazarus umbrella into six clusters spanning espionage, financial theft, and fake IT worker operations.

New research by Sekoia and Kudelski Security, published September 7, divides the former Lazarus umbrella into TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima, mostly under North Korea's military intelligence bureau (GRIB). The former APT38 likely split into CryptoCore and Jade Sleet, focused on cryptocurrency, Web3, and blockchain targets. Moonstone Sleet combines espionage with financially motivated operations, using custom malware alongside Qilin ransomware-as-a-service. Thousands of fake IT workers generate regime revenue and provide access, linked to incidents like the $62.5M Munchables protocol theft.

  • Lazarus umbrella split into six clusters based on TTPs and operations
  • Former APT38 likely divided into CryptoCore and Jade Sleet
  • Moonstone Sleet pairs espionage with Qilin RaaS and custom malware
  • Fake IT worker program tied to $62.5M Munchables theft
  • Fake IT workers aid sanctions evasion and espionage access
Full article425 words · extracted from infosecurity-magazine.com · click to collapse

North Korea's Lazarus umbrella operates as six distinct cyber clusters, according to a new analysis of the country's offensive cyber capabilities.

Sekoia and Kudelski Security said the organization reflected a broader effort by North Korea to distribute cyber operations across units focused on espionage, financial activity and sanctions evasion.

The research, published on September 7, categorized the former Lazarus umbrella into TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima.

Lazarus Umbrella Divided Into Six Clusters

The researchers said North Korean cyber units had been repeatedly reorganized and renamed, complicating attribution and making the country's cyber structure difficult to map. Most of the threat actors examined sit under the GRIB, North Korea's main military intelligence bureau, formerly known as the RGB.

Sekoia and Kudelski Security said their latest clustering was based on tactics, techniques and procedures (TTPs) and the types of operations conducted by each group. Famous Chollima was distinguished by activity linked to fake IT workers, which the researchers said often supported the objectives of other cyber units.

Among the six, Moonstone Sleet combined cyberespionage with financially motivated operations, using its own custom malware alongside the Qilin ransomware-as-a-service (RaaS) platform. The researchers said a separate DPRK-nexus cluster, Andariel, followed a similar dual-mandate pattern.

Read more on North Korean cyber operations: Lazarus Group Targets Developers in New Data Theft Campaign

The researchers also said the former APT38 cluster had likely split into CryptoCore and Jade Sleet, which they said were now focused on financial campaigns targeting cryptocurrency, Web3 and blockchain organizations.

IT Workers Extend the Cyber Operation

Alongside the APT clusters, North Korea's cyber capability included thousands of IT workers operating under false identities, according to the report.

Sekoia and Kudelski Security said these workers generated revenue for the regime while gaining access to organizations through legitimate employment. In some cases, workers queried internal corporate documentation or used access obtained through remote consulting roles to conduct further activity.

The report separately linked fake IT workers to direct cryptocurrency theft, including a $62.5m exploit of the Munchables protocol. It added that the IT worker program served both financial and operational purposes. Salaries were remitted to North Korea to help circumvent sanctions, while access obtained through employment could also support financial theft or espionage.

The wider ecosystem included front companies, educational institutions and third-country infrastructure in places including China, Russia, Southeast Asia and Africa. These networks provided operational cover, access and mechanisms for moving illicit funds.

Sekoia and Kudelski Security said the distinction between espionage and revenue generation is less firm than it appears.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/north-korea-lazarus-six-cyber/