Research Details New Lazarus Group Structure

North Korea's Lazarus Group Operations Decomposed into Six Clusters

HIGH
September 7, 2026
5m read
Threat ActorThreat IntelligenceCyberattack

Related Entities

Threat Actors

Lazarus Group TEMP.HermitCitrine SleetCryptoCoreJade SleetMoonstone SleetFamous ChollimaAPT38

Organizations

Sekoia Kudelski Security General Reconnaissance Bureau (GRIB)

Other

North KoreaQilin

Full Report

Executive Summary

A joint intelligence report from security firms Sekoia and Kudelski Security has provided an updated model for understanding North Korea's state-sponsored cyber operations. The research, published September 7, 2026, posits that the monolithic entity known as the Lazarus Group is better understood as a collection of at least six distinct operational clusters. These sub-groups, most of which are directed by North Korea's General Reconnaissance Bureau (GRIB), exhibit specialized tactics, techniques, and procedures (TTPs) tailored to specific missions, including cyberespionage, large-scale financial theft, and revenue generation to bypass international sanctions.


Threat Overview

The report moves beyond the general attribution of Lazarus and provides a more granular breakdown of the Democratic People's Republic of Korea's (DPRK) cyber capabilities. This new framework helps defenders and threat intelligence analysts better attribute specific campaigns and anticipate future targets. The six identified clusters are:

  • TEMP.Hermit
  • Citrine Sleet
  • CryptoCore
  • Jade Sleet
  • Moonstone Sleet
  • Famous Chollima

This structure reflects a sophisticated division of labor. For example, the financially-motivated activities previously associated with APT38 are now believed to be split between the CryptoCore and Jade Sleet clusters. These groups are highly focused on targeting cryptocurrency exchanges, DeFi protocols, and other Web3-related entities to steal digital assets.

Technical Analysis

The report details how different clusters employ varied TTPs. Moonstone Sleet, for instance, demonstrates a hybrid mission, conducting both traditional cyberespionage and financially motivated attacks. This cluster has been observed using its own custom malware alongside the Qilin ransomware-as-a-service (RaaS) platform, indicating a pragmatic approach to revenue generation.

The entire ecosystem is supported by a global network of facilitators. This includes:

  • IT Workers: Thousands of North Korean IT professionals work remotely for foreign companies under false identities. They serve a dual purpose: earning legitimate salaries that are funneled back to the regime and acting as insider threats to gain initial access to corporate networks. The Famous Chollima cluster is linked to this program, which was implicated in the $62.5 million Munchables protocol exploit.
  • Infrastructure: The clusters leverage front companies and infrastructure located in countries like China, Russia, and nations in Southeast Asia and Africa to launder stolen funds and obscure their operational footprint.

MITRE ATT&CK Techniques

Based on the described activities, these clusters employ a wide range of techniques, including:

Impact Assessment

This refined understanding of the DPRK's cyber apparatus underscores the multifaceted and persistent threat it poses. By segmenting operations, the regime can pursue multiple strategic objectives simultaneously while making attribution more complex. The focus on cryptocurrency and DeFi platforms continues to result in nine-figure thefts, directly funding the country's weapons programs and economy. The use of RaaS platforms like Qilin shows a dangerous convergence of state-sponsored and cybercriminal ecosystems. Furthermore, the IT worker program represents a deeply concerning supply chain and insider threat risk for any company that hires remote technical talent without rigorous background checks.

Detection & Response

  • Enhanced Vetting: Companies hiring remote IT workers, especially in development or DevOps roles, must implement stringent identity verification and background check processes.
  • Monitor Cryptocurrency Transactions: Financial institutions and crypto exchanges should enhance monitoring for transactions linked to known DPRK-controlled wallets and mixers.
  • Behavioral Analysis: For insider threats, focus on behavioral analytics. Monitor for developers accessing sensitive code repositories outside of normal working hours, large data transfers, or attempts to disable security controls.
  • Threat Intelligence Integration: Ingest IOCs and TTPs associated with the newly defined clusters (Jade Sleet, Moonstone Sleet, etc.) into SIEM and threat intelligence platforms to improve detection of specific campaigns.

Mitigation

  • User Training: Train employees, particularly in finance and engineering, to recognize sophisticated social engineering and phishing attempts targeting the cryptocurrency industry.
  • Access Control: Implement strict access controls and the principle of least privilege for developers and IT staff to limit the blast radius of a potential insider.
  • Wallet Security: For organizations handling digital assets, use multi-signature wallets, enforce strict withdrawal policies, and conduct regular security audits of smart contracts.
  • Network Segmentation: Segment development and corporate networks to prevent lateral movement from a compromised IT worker's machine into critical infrastructure.

Timeline of Events

1
September 7, 2026
Sekoia and Kudelski Security publish their joint report detailing the six-cluster structure of North Korean cyber operations.
2
September 7, 2026
This article was published

MITRE ATT&CK Mitigations

Training employees, especially developers and financial staff, to identify sophisticated phishing and social engineering attacks is crucial.

Enforcing strict controls and monitoring on privileged accounts, particularly those held by remote IT workers, can mitigate insider threats.

Segmenting networks to isolate development environments from critical corporate and financial systems can prevent lateral movement.

Audit

M1047enterprise

Auditing access to sensitive code repositories and financial systems can help detect anomalous behavior from compromised or malicious insider accounts.

D3FEND Defensive Countermeasures

To counter the insider threat posed by DPRK IT workers, organizations must implement robust User Behavior Analysis (UBA). This involves establishing a baseline of normal activity for every employee, especially remote developers and system administrators. Monitor for deviations such as access to sensitive code repositories or internal systems outside of normal working hours, unusually large data transfers to external sites, or attempts to access systems unrelated to their job function. A UBA solution can automatically flag an employee who suddenly starts probing the company's financial systems or attempting to export customer data as a high-risk anomaly, allowing for swift investigation before a major breach occurs. This is particularly critical for detecting the 'insider threat' phase of a DPRK operation.

For organizations in the Web3 and DeFi space targeted by clusters like Jade Sleet, rigorous application hardening is paramount. This includes conducting thorough security audits of all smart contracts before deployment to identify and fix potential vulnerabilities. Implement strict, multi-signature controls for all administrative functions and any function that can move funds. Ensure that private keys for wallets are stored in hardware security modules (HSMs) and require multiple, geographically dispersed individuals for any transaction above a certain threshold. These hardening measures directly counter the TTPs of DPRK actors who specialize in finding and exploiting flaws in blockchain protocols to drain funds.

Implement strict egress filtering rules on corporate networks to block outbound connections to known malicious domains and IP addresses associated with DPRK infrastructure. More importantly, configure outbound filtering to deny all traffic by default and only allow connections to known-good, business-required services on standard ports. This can prevent custom malware dropped by a DPRK actor from establishing a command-and-control channel. For example, blocking all outbound traffic except for TCP 443 to a specific list of approved SaaS applications can severely hinder an attacker's ability to exfiltrate data or receive commands, effectively isolating the compromised host.

Timeline of Events

1
September 7, 2026

Sekoia and Kudelski Security publish their joint report detailing the six-cluster structure of North Korean cyber operations.

Sources & References

North Korea's Lazarus Operates Through Six Distinct Cyber Clusters
Infosecurity Magazine (infosecurity-magazine.com) September 7, 2026
Beyond Lazarus: Organization of DPRK Cyber Capabilities
Kudelski Security (kudelskisecurity.com) September 7, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

LazarusAPT38DPRKNorth KoreaThreat ActorThreat IntelligenceCryptocurrencyEspionage

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.