How North Korea Earns

Every other view on this site groups adversaries by who they are, where the victim sits, or which industry was hit. This one groups by why.

Lazarus and APT38 and TraderTraitor stealing cryptocurrency, Contagious Interview and Famous Chollima and Jasper Sleet placing fraudulent remote workers, Andariel and Moonstone Sleet deploying ransomware for cash — these are usually published as separate APT profiles. Read as a portfolio they are one funding operation with shared tooling and overlapping infrastructure, and the tooling overlap is visible in the graph below rather than asserted in prose.

This is a reference sheet, not a feed, and it is built that way deliberately. Espionage and fraud do not appear on ransomware leak sites and are rarely the subject of a public breach notification, so the twenty-three DPRK-origin groups we track hold almost no rows in an incident corpus of more than eighteen thousand. The substantive record here is the vendor reporting, the tooling and our own coverage — not a victim count, which for this set would be a measure of our sources and not of the operation.

All collections

What these have in common

Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.

ATT&CK techniques

Shared tooling

Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.

Groups

Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.

Malware and tooling

Sectors

Further reading

Our coverage

The 12 most recent of 24 briefings that mention a member of this collection.

How this list was chosen. Membership is by attributed origin and by assessed motive, drawn from vendor reporting we hold on file — FBI IC3, CISA advisories, Microsoft MSTIC, Mandiant, CrowdStrike, Kaspersky, Unit 42 and others. Andariel is genuinely mixed-motive and most of our own coverage of it concerns defence espionage rather than revenue; it is included for the ransomware activity specifically. The malware list is curated rather than joined: the ATT&CK software catalogue is anchored on families from the late 2010s while the loaders named in our 2026 reporting are newer than it. Nothing here names an individual job applicant or an employer, and nothing does so outside a cited public advisory.

Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.

Read the full analysis on IntelFusions