Decoding the world of cybersecurity

Researchers redraw North Korea’s cyber structure

Sekoia and Kudelski Security have divided the old Lazarus umbrella into six operational clusters spanning espionage, financial operations, cryptocurrency theft, and fraudulent IT-worker activity.

Researchers redraw North Korea’s cyber structure
Summary
  • The joint research divides the historical Lazarus umbrella into six clusters based on tactics and operational roles.
  • North Korean cyber operations increasingly combine espionage, revenue generation, cryptocurrency theft, and fraudulent employment.
  • Fake IT workers sit alongside intrusion groups in a wider ecosystem where legitimate enterprise access can support regime revenue and further operations.

European security researchers are challenging the usefulness of treating Lazarus as a single North Korean hacking group, arguing that the familiar label now conceals a more specialised structure spanning espionage, financial operations, cryptocurrency theft, and fraudulent employment.

Sekoia and Kudelski Security published a joint assessment on 7 September dividing the historical Lazarus umbrella into six clusters: TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima.

The researchers group the activity according to tactics, techniques, victim profiles, and operational objectives while acknowledging that North Korea’s intelligence and military structures are repeatedly reorganised and remain difficult to map from outside the country.

That uncertainty is central to the assessment rather than a flaw in it. Sekoia says the old Lazarus umbrella has become too broad to describe operationally different campaigns that can range from strategic espionage and sabotage to cryptocurrency theft and revenue generation.

Most of the clusters identified in the research conduct financially motivated operations either as a principal objective or, in the researchers’ assessment, partly to fund other activity. That reflects the increasing use of cyber operations by the North Korean state as both an intelligence capability and a source of hard currency under international sanctions.

Famous Chollima represents the fraudulent IT-worker element in the model. North Korean workers operating under false identities can secure legitimate technical employment, generate salaries for the regime, and gain authorised access to company environments.

Cyber Insider has previously covered the expansion of fake North Korean employment identities. The new research places that activity more explicitly inside a wider cyber ecosystem rather than treating it as a standalone recruitment-fraud problem.

The distinction changes the enterprise exposure. A conventional intrusion attempts to defeat a control and obtain unauthorised access. A fraudulent employee can pass through recruitment and onboarding before the organisation itself provisions an account, device, source-code access, development tooling, or cloud permissions.

Sekoia says the IT-worker population can also support other operational objectives, creating potential overlap between revenue collection, insider access, and broader offensive activity. The research describes thousands of workers using false identities worldwide.

That does not mean every fraudulent North Korean worker is simultaneously conducting an intrusion. It does mean that employment screening, contractor governance, identity proofing, privileged access, and software-development controls belong alongside more familiar malware and threat-intelligence measures when organisations assess DPRK exposure.

The wider cluster model also highlights differing objectives. Espionage-oriented actors may seek strategic or technical intelligence; financial clusters target banks, cryptocurrency, Web3, and other assets; other operations use ransomware or legitimate employment as revenue mechanisms.

Threat-actor naming remains imperfect. Different intelligence organisations use their own labels, clusters can change over time, and analysts may disagree over where one group ends and another begins. Sekoia itself notes that discrepancies remain as North Korean organisations are reorganised and renamed.

The value of the six-cluster model lies less in producing a permanent organisational chart than in preventing a single famous name from flattening several distinct risks. An organisation facing a cryptocurrency theft operation, a fake developer, and an espionage campaign is not facing the same access path or business consequence simply because all three ultimately have a DPRK nexus.

For risk management, that difference is more useful than the umbrella label. North Korean operations now intersect recruitment, software development, cloud access, contractor management, cryptocurrency, traditional intrusion, and geopolitical espionage — each requiring a different understanding of how trusted access can be obtained and abused.

×