Researchers from Kudelski Security and Sekoia have released a comprehensive study on North Korean cyber operations, identifying six distinct clusters of activity previously grouped under the Lazarus Group moniker.
North Korea’s cyber activity is much bigger than Lazarus
That’s the focus of new joint research from Kudelski Security and @sekoia_io, looking at how DPRK cyber operations fit together across espionage, revenue generation, fake IT workers and the wider networks that support it pic.twitter.com/t5GXeEnKI8
— Kudelski Security (@KudelskiSec) September 7, 2026
The researchers categorized the activities based on tools, infrastructure, tactics, and target types. They clarified that the rebranding was necessary due to the frequent reorganizations and specialization shifts within North Korean units, which led to the single label of Lazarus obscuring the differences among various operators.
The new classification includes TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima. This taxonomy is a proprietary classification by Kudelski Security and Sekoia, rather than an officially recognized structure of North Korea's state cyber units.
Proposed classification of North Korean cyber activity clusters. Source: Kudelski Security, Sekoia.Financial Activities
According to the researchers, between 2018 and 2023, the activities attributed to Lazarus underwent organizational changes, leading to a specialization among clusters. This shift coincided with the expansion of the global cryptocurrency market.
One of the financially motivated clusters identified is APT38, linked to operations potentially conducted by the 110th Research Institute of the Main Intelligence Directorate of North Korea (GRIB, formerly RGB).
APT38 has been known for targeting the cryptocurrency sector and Web3 projects. The researchers now suggest that APT38 has likely split into two distinct clusters: CryptoCore and Jade Sleet.
“These two clusters focus exclusively on financially motivated campaigns, likely aimed at generating revenue for the regime,” the study states.
The authors do not claim that CryptoCore and Jade Sleet are official North Korean cyber units; rather, they represent two sets of observed activities that have been differentiated based on technical and operational characteristics.
This new classification also highlights the challenges associated with naming North Korean groups. The same or related operators may be referred to by different names across various research entities.
For instance, in February 2025, the FBI confirmed that the TraderTraitor group was responsible for the attack on Bybit. Authorities also track this group under the names Lazarus Group, APT38, BlueNoroff, and Stardust Chollima.
IT Workers
Another cluster identified by the researchers is Famous Chollima, which encompasses the activities of North Korean IT workers who secure jobs in foreign companies using false identities.
This scheme allows them to generate foreign currency revenue through salaries, but researchers view it as a potential means to access the internal infrastructure of these organizations. Observations indicate that these workers often study corporate documentation during their employment and may utilize their access for financial or intelligence purposes.
Kudelski Security found that IT specialists and operators involved in offensive campaigns sometimes used the same outgoing VPN nodes. The authors propose several explanations: some workers may be blending regular employment with cyber operations or collaborating with groups inside North Korea.
The researchers believe that the distinction between earning income and espionage in these operations is blurred. Access gained for financial gain could also be leveraged for information gathering, with the same infrastructure serving multiple purposes.
The report appends details about overlaps with infrastructure previously linked to the Bybit attack. For example, the IP address 66[.]118[.]255[.]35, noted among the outgoing nodes of North Korean IT workers, is associated with data from Silent Push.
Overlap of North Korean IT workers' infrastructure with known cyber campaigns. Source: Kudelski Security, Sekoia.Espionage and Revenue Generation
The study reveals that the financial activities of North Korean-linked groups extend beyond cryptocurrency theft. Several intelligence-oriented clusters simultaneously conduct operations to generate revenue.
Among these groups is Moonstone Sleet, which in 2024 employed its ransomware known as FakePenny, and in 2025 transitioned to using Qilin. This operates on a Ransomware as a Service (RaaS) model, where operators provide other groups with the necessary infrastructure and tools for conducting attacks.
A similar tactic was previously observed in the North Korean-linked group Andariel, which used its own ransomware, Maui and H0lyGh0st, and collaborated with operators of Play in 2024.
Moonstone Sleet and Andariel adopted third-party RaaS services with a gap of about two months. The authors interpret this as another instance of the convergence between state cyber operations and criminal market tools.
The researchers estimate that nearly all the North Korean clusters they identified are engaged in activities capable of generating income. For some, revenue generation is the primary objective, while others may use this means to fund intelligence and sabotage operations.
Source: Kudelski Security, Sekoia.The authors assert that cyber operations have become a multifaceted tool for Pyongyang, serving as a means for intelligence gathering, circumventing international sanctions, and generating funds. Since the mid-2010s, this model has included bank heists, ransomware attacks, and large-scale cryptocurrency thefts.
Additionally, in August, The Wall Street Journal aired an investigative documentary on the network of North Korean IT workers employed by American companies. One of the groups studied submitted applications to over 1,000 organizations within three months.
