Breaking
Cyber CrimeDeveloping Story

Lazarus Split Reveals DPRK Cyber Structure

New research maps North Korea's Lazarus umbrella into six distinct cyber clusters with specialized roles.

··3 hours ago·3 min read
a fence covered in many different colored ribbons
Photo by Christopher Pap de Pestény on Unsplash

North Korea's Lazarus umbrella, long treated as a single threat actor, operates as six distinct cyber clusters, according to a new analysis from Sekoia and Kudelski Security. The research, published on September 7, said the organization reflects a broader effort by North Korea to distribute cyber operations across units focused on espionage, financial activity, and sanctions evasion.

Six Clusters Under One Umbrella

Researchers from Sekoia and Kudelski Security categorized the former Lazarus umbrella into TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima. The researchers said that North Korean cyber units had been repeatedly reorganized and renamed, which complicates attribution and makes the country's cyber structure difficult to map.

Most of the threat actors examined sit under the GRIB, North Korea's main military intelligence bureau, formerly known as the RGB. The latest clustering is based on tactics, techniques, and procedures (TTPs) and the types of operations conducted by each group.

Different Roles for Different Units

Famous Chollima was distinguished by activity linked to fake IT workers, which the researchers said often supported the objectives of other cyber units. Moonstone Sleet combined cyberespionage with financially motivated operations, using its own custom malware alongside the Qilin ransomware-as-a-service (RaaS) platform.

The researchers said a separate DPRK-nexus cluster, Andariel, followed a similar dual-mandate pattern. The former APT38 cluster had likely split into CryptoCore and Jade Sleet, which they said were now focused on financial campaigns targeting cryptocurrency, Web3, and blockchain organizations.

Fake IT Workers Extend Operations

Alongside the APT clusters, North Korea's cyber capability included thousands of IT workers operating under false identities, according to the report. These workers generated revenue for the regime while gaining access to organizations through legitimate employment.

In some cases, workers queried internal corporate documentation or used access obtained through remote consulting roles to conduct further activity. The report separately linked fake IT workers to direct cryptocurrency theft, including a $62.5m exploit of the Munchables protocol.

Sanctions Evasion and Espionage

The IT worker program served both financial and operational purposes, the report said. Salaries were remitted to North Korea to help circumvent sanctions, while access obtained through employment could also support financial theft or espionage.

The wider ecosystem included front companies, educational institutions, and third-country infrastructure in places including China, Russia, Southeast Asia, and Africa. These networks provided operational cover, access, and mechanisms for moving illicit funds.

Blurred Lines Between Missions

Sekoia and Kudelski Security said the distinction between espionage and revenue generation is less firm than it appears. The reorganization of units into specialized clusters aligns with North Korea's broader strategic needs, but the overlap between financial and espionage operations means these units often share tools, tactics, and personnel.

  • Lazarus umbrella divided into six clusters: TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, Famous Chollima
  • $62.5m exploit of the Munchables protocol linked to fake IT workers
  • Thousands of IT workers operating under false identities

Why This Matters for Defenders

The reorganization of North Korean cyber units into specialized clusters has direct implications for organizations trying to defend against them. Rather than tracking a single monolithic threat actor, security teams now need to understand which cluster they are likely to face and tailor their defenses accordingly.

This suggests that organizations in cryptocurrency, Web3, and blockchain sectors should pay particular attention to CryptoCore and Jade Sleet, while those concerned about espionage may need to focus on Moonstone Sleet or Famous Chollima. The use of fake IT workers also highlights a supply chain risk: legitimate-looking employees may pose an insider threat, and due diligence on remote hires is increasingly important.

#lazarus#north korea#apt#cyberespionage#ransomware#cryptocurrency

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories