Mandiant published research linking prominent North Korean cyber activity to specific state organizations, arguing that multiple DPRK threat clusters commonly grouped under broad labels such as Lazarus are better understood as distinct teams aligned to different government entities. The report maps operations to the Reconnaissance General Bureau (RGB) and other North Korean institutions, and says the country’s cyber apparatus supports intelligence collection, financial theft, disruptive attacks, and strategic espionage.
The assessment highlights how umbrella naming has obscured operational differences among DPRK actors, including variations in targeting, tooling, and mission sets. By tying intrusion groups to government structures rather than relying only on overlapping malware or public aliases, Mandiant says defenders can improve attribution, track campaigns more accurately, and better understand how North Korea organizes cyber operations in support of state objectives.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Mandiant released a report titled "Not So Lazarus: Mapping DPRK Cyber Threat Groups to Government Organizations," presenting attribution analysis linking North Korean cyber threat groups to specific government entities.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.