Malware, Phishing, Ransomware, Threat Intelligence, IAM Technologies, Breach, Critical Infrastructure Security

North Korea’s Lazarus cyber umbrella divided into six clusters

North Korea's Lazarus umbrella operates as six distinct cyber clusters, according to a new analysis of the country's offensive cyber capabilities. Sekoia and Kudelski Security stated that the organization reflects a broader effort by North Korea to distribute cyber operations across units focused on espionage, financial activity, and sanctions evasion, based on information published by Infosecurity Magazine.

The research categorized the former Lazarus umbrella into TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima. North Korean cyber units have been repeatedly reorganized, complicating attribution. Famous Chollima is distinguished by activity linked to fake IT workers, often supporting other cyber units. Moonstone Sleet combines cyberespionage with financially motivated operations, using custom malware and the Qilin ransomware-as-a-service platform. CryptoCore and Jade Sleet, likely splits from the former APT38 cluster, focus on financial campaigns targeting cryptocurrency, Web3, and blockchain organizations.

Thousands of IT workers operating under false identities generate revenue and gain access to organizations. These workers facilitate cryptocurrency theft, including a $62.5 million exploit of the Munchables protocol, and support both financial and operational purposes. The wider ecosystem includes front companies, educational institutions, and third-country infrastructure in China, Russia, Southeast Asia, and Africa, providing operational cover and mechanisms for moving illicit funds.

Source: Infosecurity Magazine

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

You can skip this ad in 5 seconds