Lazarus Splinters Into Six Specialized Clusters

Sekoia and Kudelski Security said on September 7 that North Korea’s Lazarus umbrella now breaks into six distinct cyber clusters, rather than one monolithic actor. The groups they map include TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima. Their analysis ties each cluster to different jobs: espionage, cryptocurrency theft, ransomware use, sanctions evasion, and fake IT worker activity. That matters because the same state-linked access, infrastructure and tradecraft can be reused across those missions, and legitimate employment can become a foothold for later internal visibility or abuse. For defenders, the point is that attribution and containment can no longer stop at a single Lazarus label. If a contractor, remote developer or consulting account is the entry point, the operational blast radius may reach beyond one campaign into a wider DPRK support ecosystem.

Part of the PlainSec briefing for 2026-09-08

Every edition of this story: Lazarus Splinters Into Six Specialized Clusters

Sources