North Korea's hacking machine is bigger than Lazarus

Published

For a decade the name Lazarus has stood in for almost everything North Korea does online. A joint report published on 7 September by Sekoia's Threat Detection and Research team and Kudelski Security argues that the label now hides more than it reveals, and breaks the umbrella into six separate activity clusters: TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima.

That matters beyond taxonomy. The six clusters have different targets, different tooling and different reasons to be inside a network.

One umbrella name, six different crews

The researchers place the split between 2018 and 2023, as Pyongyang's operator base grew and the work specialised into espionage on one side and revenue on the other. Famous Chollima is the odd one out. It is not an intrusion set in the usual sense but the fake IT worker operation, North Korean nationals and recruited foreigners who take salaried technical jobs abroad and route wages and access back home. Kimsuky gets similar treatment, described as a mega cluster whose branches other trackers already name separately, including TA406 and TA408.

Two clusters show how thin the line between spying and earning has become. Andariel has used ransomware of its own, Maui and H0lyGh0st, and has also rented a Russian crew's ransomware as a service, working alongside Play in 2024. Moonstone Sleet deployed its custom FakePenny in 2024 and then Qilin's service in 2025. The two adopted rented ransomware within two months of each other.

Two agencies changed names this year

The structural half of the report is the harder half to see from outside. The Reconnaissance General Bureau, formed in 2009 out of several older intelligence organs and reporting straight to Kim Jong-un rather than through the army chain of command, is now the General Reconnaissance and Information Bureau. Its administrative military designation is KPA Unit 586. The Ministry of State Security, the internal security and counterintelligence service, was renamed the National Intelligence Agency in June 2026, which the authors read as an expansion into foreign missions, with the Ministry of Public Security likely picking up domestic policing.

Both changes followed the 2026 constitutional revision that stripped reunification with the South out of North Korean law. The report is blunt about why the boxes keep moving: splitting intelligence missions across rival agencies keeps them competing for the leader's favour and watching one another, which serves regime survival rather than efficiency.

The money is the mission, not a side effect

From roughly 2014 the report traces a shift from pure espionage and sabotage toward bank heists, ransomware and cryptocurrency theft, running from the $101 million Bangladesh Bank theft in 2016 to the $1.5 billion Bybit theft in 2025, and reportedly generating hundreds of millions to over a billion dollars a year. Almost every cluster described earns, either as its primary objective or to self fund espionage work.

Track the cluster, not the brand

For anyone writing detections or briefing a board, the practical change is procedural rather than technical. An intrusion labelled Lazarus tells you the sponsor and very little else, so tie rules and hunts to a specific cluster's tooling and victimology instead. Recent North Korean activity bears that out: a backdoor hidden inside a load balancer and fake staff turning up in healthcare and sales roles share a sponsor and almost nothing else. The full research is in the original report by Sekoia's TDR team and Kudelski Security.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions