North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Sekoia and Kudelski Security reclassify North Korea's Lazarus umbrella into six clusters spanning espionage, financial theft, and fake IT worker operations.
New research by Sekoia and Kudelski Security, published September 7, divides the former Lazarus umbrella into TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima, mostly under North Korea's military intelligence bureau (GRIB). The former APT38 likely split into CryptoCore and Jade Sleet, focused on cryptocurrency, Web3, and blockchain targets. Moonstone Sleet combines espionage with financially motivated operations, using custom malware alongside Qilin ransomware-as-a-service. Thousands of fake IT workers generate regime revenue and provide access, linked to incidents like the $62.5M Munchables protocol theft.
Week in review: Attackers trying to access Check Point VPNs, NIST CSF 2.0 security metrics evolution
ATF confirms cyberattack hit system containing info on its investigation targets
Qilin ransomware group claimed breaching the ATF, exposing data on investigation targets; the agency says a standalone system was hit with no mission impact.
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cyberattack on a standalone system holding information about targets of ATF investigations, designated a major incident, with no impact on case management, lab, or eForms systems. Qilin, a Russian-speaking affiliate-based ransomware group, claimed responsibility, though ATF declined to confirm involvement or the root cause. Qilin has claimed hundreds of victims across 60+ countries since 2022 and partners with Scattered Spider and Moonstone Sleet.
Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks
CISA, FBI, and South Korean agencies warn Gunra ransomware, with 51 victims since April 2025, exploits Fortinet flaws for double-extortion attacks on critical infrastructure.
CISA, the FBI, and South Korean agencies warned of Gunra ransomware attacks targeting healthcare, financial services, government, and professional services worldwide. The Conti-derived operation exploits internet-facing Fortinet FortiOS and FortiProxy flaws CVE-2024-55591 and CVE-2025-24472 for initial access, then deploys double extortion with Salsa20/ChaCha20 encryption and publishes non-payers on a leak site within five to seven days. Ransomware.Live lists 51 victims since April 2025, mostly in South Korea, Brazil, Spain, Thailand, and Hong Kong. The group uses Impacket tools for SMB lateral movement and NTDS credential dumping, tampers with VDI authentication to accept a designated OTP value to bypass MFA, and launched a RaaS affiliate program in January 2026 under the new alias Golden Community.