A joint intelligence report from security firms Sekoia and Kudelski Security has provided an updated model for understanding North Korea's state-sponsored cyber operations. The research, published September 7, 2026, posits that the monolithic entity known as the Lazarus Group is better understood as a collection of at least six distinct operational clusters. These sub-groups, most of which are directed by North Korea's General Reconnaissance Bureau (GRIB), exhibit specialized tactics, techniques, and procedures (TTPs) tailored to specific missions, including cyberespionage, large-scale financial theft, and revenue generation to bypass international sanctions.
The report moves beyond the general attribution of Lazarus and provides a more granular breakdown of the Democratic People's Republic of Korea's (DPRK) cyber capabilities. This new framework helps defenders and threat intelligence analysts better attribute specific campaigns and anticipate future targets. The six identified clusters are:
This structure reflects a sophisticated division of labor. For example, the financially-motivated activities previously associated with APT38 are now believed to be split between the CryptoCore and Jade Sleet clusters. These groups are highly focused on targeting cryptocurrency exchanges, DeFi protocols, and other Web3-related entities to steal digital assets.
The report details how different clusters employ varied TTPs. Moonstone Sleet, for instance, demonstrates a hybrid mission, conducting both traditional cyberespionage and financially motivated attacks. This cluster has been observed using its own custom malware alongside the Qilin ransomware-as-a-service (RaaS) platform, indicating a pragmatic approach to revenue generation.
The entire ecosystem is supported by a global network of facilitators. This includes:
Based on the described activities, these clusters employ a wide range of techniques, including:
T1566 - Phishing: For initial access, often targeting employees in the crypto and finance sectors.T1655 - Acquire and/or Steal Web-based Digital Currency: The primary objective of clusters like CryptoCore and Jade Sleet.T1589 - Gather Victim Identity Information: A key part of the IT worker infiltration scheme, where they establish credible false identities.T1059.005 - Visual Basic: Often used in malicious documents for initial compromise.T1190 - Exploit Public-Facing Application: Used to gain access to vulnerable servers, especially in the DeFi space.This refined understanding of the DPRK's cyber apparatus underscores the multifaceted and persistent threat it poses. By segmenting operations, the regime can pursue multiple strategic objectives simultaneously while making attribution more complex. The focus on cryptocurrency and DeFi platforms continues to result in nine-figure thefts, directly funding the country's weapons programs and economy. The use of RaaS platforms like Qilin shows a dangerous convergence of state-sponsored and cybercriminal ecosystems. Furthermore, the IT worker program represents a deeply concerning supply chain and insider threat risk for any company that hires remote technical talent without rigorous background checks.
Training employees, especially developers and financial staff, to identify sophisticated phishing and social engineering attacks is crucial.
Enforcing strict controls and monitoring on privileged accounts, particularly those held by remote IT workers, can mitigate insider threats.
Segmenting networks to isolate development environments from critical corporate and financial systems can prevent lateral movement.
To counter the insider threat posed by DPRK IT workers, organizations must implement robust User Behavior Analysis (UBA). This involves establishing a baseline of normal activity for every employee, especially remote developers and system administrators. Monitor for deviations such as access to sensitive code repositories or internal systems outside of normal working hours, unusually large data transfers to external sites, or attempts to access systems unrelated to their job function. A UBA solution can automatically flag an employee who suddenly starts probing the company's financial systems or attempting to export customer data as a high-risk anomaly, allowing for swift investigation before a major breach occurs. This is particularly critical for detecting the 'insider threat' phase of a DPRK operation.
For organizations in the Web3 and DeFi space targeted by clusters like Jade Sleet, rigorous application hardening is paramount. This includes conducting thorough security audits of all smart contracts before deployment to identify and fix potential vulnerabilities. Implement strict, multi-signature controls for all administrative functions and any function that can move funds. Ensure that private keys for wallets are stored in hardware security modules (HSMs) and require multiple, geographically dispersed individuals for any transaction above a certain threshold. These hardening measures directly counter the TTPs of DPRK actors who specialize in finding and exploiting flaws in blockchain protocols to drain funds.
Implement strict egress filtering rules on corporate networks to block outbound connections to known malicious domains and IP addresses associated with DPRK infrastructure. More importantly, configure outbound filtering to deny all traffic by default and only allow connections to known-good, business-required services on standard ports. This can prevent custom malware dropped by a DPRK actor from establishing a command-and-control channel. For example, blocking all outbound traffic except for TCP 443 to a specific list of approved SaaS applications can severely hinder an attacker's ability to exfiltrate data or receive commands, effectively isolating the compromised host.
Sekoia and Kudelski Security publish their joint report detailing the six-cluster structure of North Korean cyber operations.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.