Security News

North Korea's Lazarus Group Splits Into Six Specialised Hacking Units

Infosecurity Magazine · 7 Sept 2026
Key Takeaway Australian small businesses hiring remote IT or development contractors should verify identities thoroughly, as North Korean operatives are known to infiltrate organisations through legitimate-looking employment.

A joint analysis by Sekoia and Kudelski Security, published on 7 September, has mapped North Korea's offensive cyber capability into six separate clusters operating under the former Lazarus umbrella: TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima. Most of these groups fall under North Korea's main military intelligence bureau, formerly known as the RGB and now called the GRIB. Researchers noted that repeated reorganisation and renaming of these units has made attribution increasingly difficult.

Each cluster appears to specialise, though several blend objectives. Moonstone Sleet, for example, combines espionage with financially motivated attacks, using custom malware alongside the Qilin ransomware-as-a-service platform, a pattern also seen in a related cluster called Andariel. CryptoCore and Jade Sleet, believed to be offshoots of the former APT38 group, focus on financial theft targeting cryptocurrency, Web3 and blockchain firms. Famous Chollima stands out for its association with fake IT worker schemes, which the researchers say often support the goals of the other clusters.

The report also highlights that thousands of North Korean IT workers operate under false identities in legitimate jobs, generating revenue for the regime while gaining insider access to organisations. In some cases, this access was reportedly used to query internal company documents or support further malicious activity.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.