$62.5m: that is the single cryptocurrency theft the researchers link to North Korea’s program of fake IT workers, a striking figure that sits at the intersection of crime, statecraft and corporate infiltration.
Six distinct clusters now make up the Lazarus umbrella
On September 7, researchers at Sekoia and Kudelski Security published an analysis that reframes North Korea’s offensive cyber apparatus. What was broadly described in past reporting as the Lazarus umbrella is recast as six discrete clusters: TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima. The researchers said their clustering is grounded in observed tactics, techniques and procedures (TTPs) and the operational focus of each group.
They noted that North Korean cyber units have been repeatedly reorganized and renamed, complicating attribution. Most of the threat actors the researchers examined sit under the GRIB, North Korea’s main military intelligence bureau, formerly known as the RGB.
Moonstone Sleet and the blurred line between espionage and revenue
Moonstone Sleet is highlighted as a hybrid operator: the cluster conducts both cyberespionage and financially motivated operations. According to Sekoia and Kudelski Security, Moonstone uses custom malware while also leveraging the Qilin ransomware-as-a-service (RaaS) platform. The researchers emphasized that the division between espionage and revenue generation within these clusters is less firm than conventional models suggest.
A separate DPRK-nexus cluster named Andariel was described as following a similar dual-mandate pattern, further reinforcing the observation that intelligence collection and profit-seeking activities can coexist within the same operational units.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildCryptoCore and Jade Sleet: APT38’s apparent fragmentation
The analysis posits that the former APT38 cluster has likely split into two new clusters, CryptoCore and Jade Sleet. Both are said to be focused on financial campaigns that target the cryptocurrency ecosystem: cryptocurrency exchanges, Web3 projects and blockchain organizations. The split, in the researchers’ view, represents an organizational shift toward specialization within North Korea’s broader effort to generate sanctions-evading revenue.
Famous Chollima and the fake IT worker program
Famous Chollima is distinguished in the report by activity tied to fake IT workers. Sekoia and Kudelski Security said these workers—numbering in the thousands—operate under false identities, take legitimate-seeming employment or consulting roles, and in some cases query internal corporate documentation or use their access to conduct follow-on operations.
The researchers linked that program directly to cryptocurrency theft, citing the $62.5m exploit of the Munchables protocol as an example. They described the IT worker program as serving both financial and operational purposes: salaries were remitted to North Korea to help circumvent sanctions, while access obtained through employment could support either financial theft or espionage.
Front companies, educational institutions and third-country infrastructure
Beyond technical tradecraft, the researchers document a wide ecosystem of enablers. Front companies, educational institutions and third-country infrastructure in places including China, Russia, Southeast Asia and Africa provide operational cover, access and channels for moving illicit funds. Those networks, the report says, supply both the logistical scaffolding for intrusions and the financial pathways needed to launder or transfer proceeds.
The scale and geographic spread of these supporting nodes make enforcement and interdiction more complex, according to the account provided by Sekoia and Kudelski Security.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: expect a mix of espionage and theft-focused intrusions that may originate from legitimate-looking employees and remote consultants; detection programs should expand to include behavioral monitoring of remote access and third-party accounts tied to IT contractors.
- Policymakers and sanctions enforcers: the report highlights mechanisms—salary remittances, third-country infrastructure and front companies—that are being used to evade sanctions and move funds, suggesting a need to map and disrupt financial and legal conduits as well as technical channels.
- Affected enterprises and procurement leaders: organizations in cryptocurrency, Web3 and blockchain sectors should be aware of clusters—named CryptoCore and Jade Sleet—explicitly focused on those targets, and of the risk that trusted contractors or remote consultants may be part of a broader operation.
The Sekoia and Kudelski Security analysis paints a picture of an adaptive, distributed operation: specialized cyber clusters, a large cadre of covert IT workers, and a supporting international ecosystem that blends legitimate business forms with covert aims. Taken together, those elements complicate simple separation of espionage from profit-driven crime and increase the challenge of attribution, interdiction and corporate risk management.
Original story: https://www.infosecurity-magazine.com/news/north-korea-lazarus-six-cyber/




