Researchers identify six clusters within Lazarus Group activity

In Crypto Regulations
September 10, 2026

Researchers identify six clusters within Lazarus Group activity

Researchers at Kudelski Security and Sekoia published a joint study on North Korean cyber operations. The authors identified six clusters of activity that were previously grouped under the Lazarus Group label.

The researchers grouped activity by tools, infrastructure, tactics, and target types. They said North Korean units have repeatedly reorganized and changed specialization, so the single Lazarus label has come to obscure differences among individual operators.

The new classification includes TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima. The scheme is Kudelski Security and Sekoia’s own taxonomy, not a confirmed organizational structure of DPRK state cyber units.

Снимок экрана — 2026-09-09 в 15.14.59
Proposed classification of DPRK-linked cyber activity clusters. Source: Kudelski Security, Sekoia.

Financial operations

According to the researchers, from 2018–2023 activity attributed to Lazarus underwent a reorganization, splitting clusters by specialization. This coincided with the expansion of the global crypto market.

One financially motivated line was APT38. The authors linked it to operations that may have been conducted by the 110th Research Institute of the DPRK General Reconnaissance and Information Bureau (GRIB, formerly RGB).

APT38 specialized, among other things, in attacks on the crypto industry and Web3 projects. The researchers now consider it most likely that this cluster has split into CryptoCore and Jade Sleet.

“These two clusters focus exclusively on financially motivated campaigns, likely aimed at generating revenue for the regime,” the study says.

The authors do not claim that CryptoCore and Jade Sleet are official DPRK cyber units. They refer to two sets of observed activity that specialists separated based on technical and operational indicators.

The new classification also highlights a naming problem with North Korean groups. The same or related operators may appear under multiple designations across different researchers.

For example, in February 2025 the FBI confirmed that the attack on Bybit was carried out by the TraderTraitor group. According to authorities, it is also tracked as Lazarus Group, APT38, BlueNoroff, and Stardust Chollima.

IT workers

The authors singled out Famous Chollima as a separate cluster. They attribute to it the activity of North Korean IT workers who take jobs at foreign companies under fake identities.

The scheme enables foreign-currency earnings through salaries, but the researchers also view it as a potential channel to internal corporate infrastructure. In their observations, workers reviewed corporate documentation during hiring and could use the access obtained for financial or intelligence purposes.

Kudelski Security found that in some cases IT specialists and offensive operators used the same outbound VPN nodes. The authors offered several explanations: some workers may combine regular jobs with cyber operations or interact with groups located inside the DPRK.

The researchers believe the line between income generation and espionage in such operations is blurred. Access obtained for revenue can be used to collect information, and the same infrastructure serves different tasks.

An appendix to the report separately shows an overlap with infrastructure previously linked to the Bybit attack. The IP address 66[.]118[.]255[.]35, seen among outbound nodes used by North Korean IT workers, is matched with data from Silent Push.

Снимок экрана — 2026-09-09 в 15.21.13
Overlap between infrastructure used by North Korean IT workers and known cyber campaigns. Source: Kudelski Security, Sekoia.

Espionage and revenue generation

The study shows that financial activity by DPRK-linked groups is not limited to cryptocurrency thefts. Some intelligence-focused clusters simultaneously run money-making operations.

The authors include Moonstone Sleet among such groups. In 2024 it used its own FakePenny ransomware, and in 2025 switched to Qilin. It operates on a RaaS model: operators provide other groups with ready-made infrastructure and tools to conduct attacks.

Researchers previously observed a similar tactic by the DPRK-linked group Andariel. It used its own Maui and H0lyGh0st ransomware and in 2024 worked with Play operators.

Moonstone Sleet and Andariel began using third-party RaaS services about two months apart. The authors view this as another example of state cyber operations converging with criminal-market tooling.

By the researchers’ estimate, almost all of the North Korean clusters they identified take part in revenue-generating operations. For some, making money is the primary task; others may use it to self-fund intelligence and sabotage campaigns.

HRwiq2xbYAA8Qx4
Source: Kudelski Security, Sekoia.

The authors say cyber operations have become for Pyongyang simultaneously an intelligence tool, a way to evade international sanctions, and a source of funds. Since the mid-2010s, this model has included bank heists, ransomware attacks, and large cryptocurrency thefts.

In August, The Wall Street Journal journalists released an investigative film about a network of North Korean IT workers in U.S. companies. One of the groups studied sent applications to more than 1,000 organizations in three months.

Avatar photo
/ Published posts: 1057

Steven M. Crimmins is a cryptocurrency strategist and freelance writer who has followed the blockchain industry since Bitcoin’s early days. Known for his sharp analysis of altcoins and trading strategies, Steven provides Satoshi News Africa readers with market-focused content grounded in research. He is especially interested in how African traders are adopting crypto as an alternative to traditional markets. Steven is also a podcast host, where he discusses emerging technologies and investment trends.