SEKOIA and Kudelski Security have mapped North Korea’s Lazarus umbrella into six distinct cyber clusters—TEMP[.]Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima—in a move that underlines how DPRK’s offensive cyber programme is distributed across units with combined espionage, financial and sanctions-evasion aims. The researchers emphasise that Lazarus has been repeatedly reorganised and renamed, complicating attribution and making the cyber structure hard to map.
They note that most actors sit under GRIB, North Korea’s main military intelligence bureau, previously known as RGB, and that Famous Chollima is distinguished by activity tied to fake IT workers that often support other units’ objectives. Moonstone Sleet is described as blending cyberespionage with financially motivated activity, deploying custom malware alongside the Qilin ransomware-as-a-service platform, while Andariel is identified as a DPRK-nexus group pursuing a similar dual mandate.
The former APT38 cluster is described as having split into CryptoCore and Jade Sleet, now focusing on financial campaigns targeting cryptocurrency, Web3 and blockchain organisations.
The report also highlights that thousands of IT workers operate under false identities to sustain the regime’s operations, generating revenue and gaining access through legitimate employment. In some cases, workers allegedly used internal documentation or remote consulting roles to extend activity, and there is a separate link between fake IT workers and direct crypto theft, including a $62.5 million exploit of the Munchables protocol.
The wider ecosystem includes front organisations, educational institutions and third-country infrastructure across China, Russia, South‑east Asia and Africa, providing operational cover and channels for moving illicit funds. The researchers argue that the line between espionage and revenue generation is less clear in practice.