The name "Lazarus" has long functioned as shorthand for North Korea's entire crypto-theft apparatus. A joint analysis by French threat-intelligence firm Sekoia and Kudelski Security, published September 7, argues that shorthand is now actively misleading — and offers a replacement map.

The report, "Beyond Lazarus: Organization of DPRK Cyber Capabilities", organizes the former Lazarus umbrella into six clusters: TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima. Most sit under the GRIB, North Korea's main military intelligence bureau, formerly known as the RGB.

Why the Split Matters

The researchers say North Korean cyber units have been repeatedly reorganized and renamed, complicating attribution and making the country's structure difficult to map. Their clustering is based on tactics, techniques and procedures and on the types of operations each group conducts — not on branding.

For the crypto industry, the most consequential finding concerns lineage: the researchers assess that the former APT38 cluster has likely split into CryptoCore and Jade Sleet, both now focused on financial campaigns targeting cryptocurrency, Web3 and blockchain organizations — the direct heirs of the bank-heist tradition aimed at exchanges, bridges and custodians.

Two other clusters carry direct security relevance for crypto teams. Famous Chollima is distinguished by activity linked to fake IT workers — the researchers note these operations often supported the objectives of other cyber units, and the report links fake IT workers to direct theft, including the $62.5 million exploit of the Munchables protocol. Moonstone Sleet combines cyberespionage with financially motivated operations, using custom malware alongside the Qilin ransomware-as-a-service platform; the separate DPRK-nexus cluster Andariel follows a similar dual-mandate pattern.

The Workforce Layer

Alongside the clusters, the report describes thousands of North Korean IT workers operating under false identities. The program serves both financial and operational purposes: salaries are remitted to North Korea to help circumvent sanctions, while access obtained through legitimate employment — including remote consulting roles — can support financial theft or espionage. In some documented cases, workers queried internal corporate documentation during their tenure.

The surrounding ecosystem includes front companies, educational institutions and third-country infrastructure in China, Russia, Southeast Asia and Africa, providing operational cover and mechanisms for moving illicit funds.

The researchers close on a caution that applies equally to defenders and to anyone quoting their work: the distinction between espionage and revenue generation inside North Korea's apparatus is less firm than it appears.

Attribution in this space remains assessment, not fact. The clustering reflects the researchers' evaluation of observed operations; no element of it has been adjudicated, and descriptions of cluster activity — including the Munchables link — reflect the report's attribution, which other researchers have not independently confirmed. Hiring-side defenses against fake-IT-worker infiltration and exchange-side controls against the financial clusters remain the practical takeaways.

TrustGrade tracks security posture for exchanges, protocols and platforms targeted by these actors. Registry-backed security scoring arrives with TrustGrade Code Scoring in December 2026.