Kudelski Security and Sekoia assess that the former Lazarus umbrella should be treated as six distinct DPRK-linked clusters: TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima. The groups differ in tradecraft and mission, conducting espionage, destructive activity, ransomware, bank theft, cryptocurrency theft, and sanctions-evasion operations rather than operating as a single monolithic actor.
The assessment identifies the General Reconnaissance and Information Bureau (GRIB, formerly RGB) as North Korea’s principal offensive cyber organization, supported by intelligence bodies, party oversight, overseas intermediaries, and frequently reorganized units. It also highlights fake IT-worker schemes, front companies, academic exchanges, and infrastructure across China, Russia, Southeast Asia, and parts of Africa that help generate revenue, enable access, and launder proceeds; organizations should therefore track the six clusters separately and strengthen controls against identity fraud, insider-risk hiring, and cryptocurrency-focused intrusion campaigns.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
The DPRK's Ministry of State Security was renamed the National Intelligence Agency; the assessment says the change may indicate expanded foreign-intelligence responsibilities.
Moonstone Sleet used the Qilin ransomware-as-a-service platform in addition to its custom malware operations.
The approximately $1.5 billion Bybit theft is cited as an example of DPRK-linked cryptocurrency theft.
Funds stolen in the 2024 Munchables theft were returned after the actors encountered laundering difficulties. The report links probable DPRK IT workers to the theft.
Moonstone Sleet deployed FakePenny custom malware as part of its combined cyberespionage and financially motivated activity.
Andariel was observed collaborating with the Play ransomware operation; the cluster also used the Maui and H0lyGh0st ransomware families.
Identified DPRK IT-worker communications shifted from formal Korean to English around October 2022, which the report assesses was intended to make the workers less distinctive.
The Kudelski Security and Sekoia TDR research associates North Korea-linked operations with the WannaCry campaign.
The 2016 Bangladesh Bank heist resulted in the theft of $101 million and is cited as an example of DPRK-linked financially motivated cyber activity.
Kimsuky used wiper components during the breach of Korea Hydro and Nuclear Power, according to the report.
The report attributes the Sony Pictures hack to Lazarus-associated activity.
The report attributes Operation DarkSeoul to Lazarus-associated activity.
The Reconnaissance General Bureau (RGB), later known as GRIB, was formed through the merger of the Korean People's Army Reconnaissance Bureau, the Korean Workers' Party Operations Department, and overseas intelligence functions from Office 35.
Sekoia and Kudelski Security published an assessment separating the former Lazarus umbrella into TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima. The model differentiates the clusters by tactics, techniques, procedures, and operational objectives.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceinfosec.pub
Open sourceinfosecurity-magazine.com
Open sourcesekoia.com
Open sourcekudelskisecurity.com
Open sourcejstor.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.