In a recent analysis, cybersecurity firms Sekoia and Kudelski Security revealed that North Korea’s Lazarus Group operates through six distinct cyber clusters, a development that sheds light on the country’s evolving offensive cyber capabilities. This comprehensive breakdown illustrates a deliberate strategy by North Korea to distribute its cyber operations across various units, emphasizing espionage, financial activities, and the evasion of international sanctions.
On September 7, the two research organizations published their findings, which categorize the Lazarus Group into six clusters: TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and finally, Famous Chollima. This classification reflects the complexity and ongoing evolution of North Korea’s cyber strategies, which had previously been challenging to define due to the consistent reorganization and renaming of its cyber units. The analysis highlights the fact that most of the threat actors involved belong to the General Reconnaissance Bureau (GRIB), North Korea’s primary military intelligence agency, previously referred to as the RGB.
The research presented by Sekoia and Kudelski Security utilizes a framework based on the tactics, techniques, and procedures (TTPs) employed by these groups, as well as the specific types of operations they carry out. Among these clusters, Famous Chollima has garnered attention due to its activities related to employing fake IT professionals. According to the researchers, these deceptive practices often align with the objectives of other cyber units, facilitating a more extensive range of operations under the umbrella of the Lazarus Group.
Another significant cluster, Moonstone Sleet, stands out for its dual approach, which melds cyber espionage with activities aimed at generating financial profit. This group utilizes custom malware alongside the Qilin ransomware-as-a-service (RaaS) platform, demonstrating a marked capability to engage in both intelligence gathering and financially driven cybercrime. Similar patterns were noted in a separate North Korea-connected cluster called Andariel, which also exhibits a combined focus on espionage and financial objectives.
Researchers noted that the restructuring of the former APT38 cluster likely led to the emergence of CryptoCore and Jade Sleet, clusters that are now primarily targeting financial campaigns within the realms of cryptocurrency, Web3, and blockchain technologies. This suggests a strategic pivot in focus, aligning with global trends in financial technology and the exponential growth of the cryptocurrency market.
In addition to the APT clusters identified, the report emphasized the role of thousands of IT workers equipped with false identities operating within North Korea’s cyber strategy. These individuals generate revenue for the regime while simultaneously infiltrating organizations by securing legitimate employment. The research indicates that in certain situations, these workers accessed internal corporate documents or leveraged remote consulting roles to advance further operations.
Notably, the report linked these fake IT workers to significant cryptocurrency thefts, including a recent high-profile exploit that drained approximately $62.5 million from the Munchables protocol. It asserts that the IT worker program serves critical financial and operational roles; salaries are funneled back to North Korea as a means of circumventing international sanctions. At the same time, the access gained through legitimate employment could be instrumental in supporting espionage efforts or financial theft.
The wider ecosystem that facilitates North Korea’s cyber operations encompasses a network of front companies, educational institutions, and third-country infrastructural elements located in regions such as China, Russia, Southeast Asia, and Africa. These installations not only provide necessary operational cover but also offer avenues for accessing essential resources and transferring illicit funds.
Moreover, Sekoia and Kudelski Security have suggested that the line between espionage and revenue generation is not as distinct as it may appear, indicating that the two objectives are intricately interlinked. The convergence of these activities underscores a sophisticated cyber environment in which financial gain is often a byproduct of espionage or vice versa.
As North Korea continues to refine its offensive cyber operations, the implications for global cybersecurity and international relations remain significant. Understanding the intricate structure and strategies employed by the Lazarus Group may be essential for countries and organizations looking to defend against these persistent threats.

