Researchers have uncovered evidence suggesting a rare collaboration between Russian state-sponsored threat actor Gamaredon and North Korea's Lazarus Group, marked by the sharing of command-and-control infrastructure. Gen Threat Labs identified activity from both groups on the same server, with a Gamaredon C2 address later hosting Lazarus-linked InvisibleFerret malware, which had previously been used in the Contagious Interview campaign. The server structure and delivery paths were consistent with Lazarus's known tactics, and the close timing of the activities has led researchers to believe this is more than coincidental, indicating a possible alliance that could enhance the offensive capabilities of both groups.
This potential partnership is significant as it represents a rare instance of cross-nation APT cooperation, with Gamaredon typically conducting espionage for Russia's FSB and Lazarus engaging in both espionage and financially motivated attacks for North Korea's RGB. Security experts warn that such collaboration could amplify the reach and resilience of state-sponsored cyber campaigns, urging organizations to strengthen multi-actor attribution capabilities and adopt multi-layered threat defenses. No specific vulnerabilities or exploits were cited in the reports, with the focus instead on infrastructure overlap and evolving threat attribution patterns.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
On publication of the research, analysts publicly warned that the apparent overlap between Russia's Gamaredon and North Korea's Lazarus could indicate an unusual cross-nation APT partnership. They noted the evidence was not definitive and could also reflect use of a proxy or VPN endpoint, but said the overlap was significant enough to merit closer attribution and defensive monitoring.
Gen Threat Labs reported that a known Gamaredon command-and-control IP was observed and, within days, the same server hosted an obfuscated InvisibleFerret payload associated with Lazarus's Contagious Interview campaign. Researchers said the timing, server structure, and malware lineage suggested possible shared infrastructure or operational overlap between the two groups.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.