Beyond Lazarus: Organization of DPRK Cyber Capabilities
2026-09-07 • Kudelski Security •
https://kudelskisecurity.com/research/beyond-lazarus-organization-of-dprk-cyber-capabilities
Kudelski Security and Sekoia map North Korea's offensive cyber capabilities as a distributed state system led principally by the GRIB and NIA, with frequently reorganized units conducting espionage, sabotage, ransomware, and financial theft. They divide the former Lazarus umbrella into TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima, while describing Kimsuky as another broad espionage ecosystem. Thousands of fraudulent DPRK IT workers supplement these intrusion sets by earning revenue under false identities and potentially exploiting insider access. Universities, front companies, foreign facilitators, exchanges, and criminal networks provide training, operational cover, infrastructure, and laundering channels that support sanctions evasion and weapons financing.