
Researchers at Kudelski Security and Sekoia published a joint study on North Korean cyber operations. The authors identified six clusters of activity that were previously grouped under the Lazarus Group label.
North Korea’s cyber activity is much bigger than Lazarus
That’s the focus of new joint research from Kudelski Security and @sekoia_io, looking at how DPRK cyber operations fit together across espionage, revenue generation, fake IT workers and the wider networks that support it pic.twitter.com/t5GXeEnKI8
— Kudelski Security (@KudelskiSec) September 7, 2026
The researchers grouped activity by tools, infrastructure, tactics, and target types. They said North Korean units have repeatedly reorganized and changed specialization, so the single Lazarus label has come to obscure differences among individual operators.
The new classification includes TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima. The scheme is Kudelski Security and Sekoia’s own taxonomy, not a confirmed organizational structure of DPRK state cyber units.

Financial operations
According to the researchers, from 2018–2023 activity attributed to Lazarus underwent a reorganization, splitting clusters by specialization. This coincided with the expansion of the global crypto market.
One financially motivated line was APT38. The authors linked it to operations that may have been conducted by the 110th Research Institute of the DPRK General Reconnaissance and Information Bureau (GRIB, formerly RGB).
APT38 specialized, among other things, in attacks on the crypto industry and Web3 projects. The researchers now consider it most likely that this cluster has split into CryptoCore and Jade Sleet.
“These two clusters focus exclusively on financially motivated campaigns, likely aimed at generating revenue for the regime,” the study says.
The authors do not claim that CryptoCore and Jade Sleet are official DPRK cyber units. They refer to two sets of observed activity that specialists separated based on technical and operational indicators.
The new classification also highlights a naming problem with North Korean groups. The same or related operators may appear under multiple designations across different researchers.
For example, in February 2025 the FBI confirmed that the attack on Bybit was carried out by the TraderTraitor group. According to authorities, it is also tracked as Lazarus Group, APT38, BlueNoroff, and Stardust Chollima.
IT workers
The authors singled out Famous Chollima as a separate cluster. They attribute to it the activity of North Korean IT workers who take jobs at foreign companies under fake identities.
The scheme enables foreign-currency earnings through salaries, but the researchers also view it as a potential channel to internal corporate infrastructure. In their observations, workers reviewed corporate documentation during hiring and could use the access obtained for financial or intelligence purposes.
Kudelski Security found that in some cases IT specialists and offensive operators used the same outbound VPN nodes. The authors offered several explanations: some workers may combine regular jobs with cyber operations or interact with groups located inside the DPRK.
The researchers believe the line between income generation and espionage in such operations is blurred. Access obtained for revenue can be used to collect information, and the same infrastructure serves different tasks.
An appendix to the report separately shows an overlap with infrastructure previously linked to the Bybit attack. The IP address 66[.]118[.]255[.]35, seen among outbound nodes used by North Korean IT workers, is matched with data from Silent Push.

Espionage and revenue generation
The study shows that financial activity by DPRK-linked groups is not limited to cryptocurrency thefts. Some intelligence-focused clusters simultaneously run money-making operations.
The authors include Moonstone Sleet among such groups. In 2024 it used its own FakePenny ransomware, and in 2025 switched to Qilin. It operates on a RaaS model: operators provide other groups with ready-made infrastructure and tools to conduct attacks.
Researchers previously observed a similar tactic by the DPRK-linked group Andariel. It used its own Maui and H0lyGh0st ransomware and in 2024 worked with Play operators.
Moonstone Sleet and Andariel began using third-party RaaS services about two months apart. The authors view this as another example of state cyber operations converging with criminal-market tooling.
By the researchers’ estimate, almost all of the North Korean clusters they identified take part in revenue-generating operations. For some, making money is the primary task; others may use it to self-fund intelligence and sabotage campaigns.

The authors say cyber operations have become for Pyongyang simultaneously an intelligence tool, a way to evade international sanctions, and a source of funds. Since the mid-2010s, this model has included bank heists, ransomware attacks, and large cryptocurrency thefts.
In August, The Wall Street Journal journalists released an investigative film about a network of North Korean IT workers in U.S. companies. One of the groups studied sent applications to more than 1,000 organizations in three months.
