Zero Day Room
Live
Threats

Lazarus Group Splits Into Six Cyber Clusters

North Korea's Lazarus cyber umbrella operates as six distinct clusters focused on espionage, financial theft, and sanctions evasion, according to a new

North Korea's Lazarus cyber umbrella operates as six distinct clusters focused on espionage, financial theft, and...

North Korea's Lazarus cyber operation is now structured as six distinct clusters, according to a new analysis. The research details a reorganization of the country's offensive cyber capabilities.

Sekoia and Kudelski Security said the organization reflects a broader effort by North Korea to distribute cyber operations across specialized units. Most of the threat actors examined operate under the GRIB, North Korea's main military intelligence bureau.

Six Clusters Under the Lazarus Umbrella

The researchers categorized the former Lazarus umbrella into six groups based on their tactics, techniques, and procedures. They said North Korean cyber units have been repeatedly reorganized and renamed, complicating attribution.

The six clusters identified are TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima. Famous Chollima was distinguished by activity linked to fake IT workers, which the researchers said often supports other cyber units.

Among them, Moonstone Sleet combines cyberespionage with financially motivated operations. It uses its own custom malware alongside the Qilin ransomware-as-a-service platform. The researchers said a separate DPRK-nexus cluster, Andariel, follows a similar dual-mandate pattern.

The former APT38 cluster has likely split into CryptoCore and Jade Sleet. These groups are now focused on financial campaigns targeting cryptocurrency, Web3, and blockchain organizations.

Fake IT Workers Extend Operations

Alongside the APT clusters, North Korea's cyber capability includes thousands of IT workers operating under false identities. Sekoia and Kudelski Security said these workers generate revenue for the regime while gaining access to organizations through legitimate employment.

In some cases, workers queried internal corporate documentation. They also used access obtained through remote consulting roles to conduct further activity. The report separately linked fake IT workers to direct cryptocurrency theft, including a $62.5 million exploit of the Munchables protocol.

The IT worker program serves both financial and operational purposes. Salaries are remitted to North Korea to help circumvent sanctions. Access obtained through employment can also support financial theft or espionage.

A Wider Ecosystem for Cover and Funding

The wider ecosystem includes front companies, educational institutions, and third-country infrastructure. These networks are located in places including China, Russia, Southeast Asia, and Africa. They provide operational cover, access, and mechanisms for moving illicit funds.

The researchers said the distinction between espionage and revenue generation is less firm than it appears. The report shows how North Korea's cyber operations are deeply integrated with its efforts to evade international sanctions and fund its regime.

Related coverage

More from Threats