Security1 publisher3 min readPublished
Sekoia and Kudelski split the Lazarus umbrella into six DPRK sub-clusters
The joint research argues that constant reorganization under the GRIB and NIA is a control mechanism rather than administrative noise, and that treating Lazarus as one actor hides the revenue mandate driving most of the intrusions.
The Watch · Security desk

What happened
- Sekoia and Kudelski Security have decomposed the former Lazarus umbrella into six distinct sub-clusters, and say nearly all of them run money-making operations either as their mandate or to fund themselves.
- Thousands of IT workers under false identities sit alongside the APT sets, remitting salaries and using insider access at contracting employers, with proceeds laundered through centralized exchanges, DEXs and P2P platforms.
- The paper is joint work by Kudelski Security and Sekoia, credited to Clifford of Kudelski plus Coline Chavane, Saee Vaidya and the Sekoia threat detection and research team.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Organizations contracting remote engineering talent sit inside the org chart: the hire is the access path, and it arrives through HR rather than through an alert.
- precedent Naming bureaus in sanctions designations becomes a slower-moving target than the units being named, which favours designating people and wallets over boxes on a chart.
- contradiction Vendors that keep reporting one Lazarus and vendors adopting a six-way split will produce reports that cannot be correlated, and consumers of both will be merging distinct actors without knowing it.
The mechanism is what makes this operationally useful. Kudelski Security and Sekoia say the units and bureaus below the GRIB (formerly the RGB) and the NIA (formerly the MSS) are reorganized constantly, and that the churn is a deliberate control mechanism: it keeps agencies competing for Kim Jong-un's favor and stops any of them consolidating independent power [3]. The side effect abroad is that attribution and sanctions designation get harder [3]. A designation names a bureau. If the bureau's mandate moves, the designation ages out while the operators do not.
The sources assert that complicating effect on foreign governments, but they do not measure it: the research does not publish a count of mis-attributions, a list of designations rendered stale, or a mapping from named public reporting to the wrong cluster [3][4]. So the argument that intel teams keep mis-attributing because they track one Lazarus is a plausible reading of the structure, not something demonstrated in the paper.
The cluster decomposition is the concrete deliverable. Six sub-clusters, and nearly all of them run lucrative operations, either as their primary mandate or to self-fund espionage and sabotage [4]. Read that against the 2014 turn, when cyber went from espionage and sabotage to a load-bearing revenue stream through bank heists, ransomware and cryptocurrency theft, financing the weapons programmes sanctions were meant to constrain [2]. If nearly all six monetize, then a crypto theft or a ransomware deployment narrows the field barely at all: on the paper's own decomposition, a revenue motive is close to a null signal for telling the sub-clusters apart. The discriminator is tooling and infrastructure, not the purpose the intrusion served.
The two authors also put the IT worker programme on the same org chart, not off to one side. Thousands of workers operate under false identities worldwide, remitting salaries to the regime and using their insider access inside contracted organizations to run further operations, with proceeds laundered through centralized exchanges, DEXs and P2P platforms [5]. That is a supply-chain exposure for anyone who contracts remote engineering talent, and it does not look like an intrusion when it starts.
Around all of it sits the enabling layer: academic institutions that both train operatives and serve as operational nodes [6], and a web of third-country relays reaching into China and Russia as well as countries in Africa and Southeast Asia, where front companies generate revenue and provide cover and criminal networks are used for laundering [7]. Doctrine ties it together. The researchers describe cyber as a cheap, deniable "all-purpose sword" sitting alongside nuclear weapons in an asymmetric deterrence posture aimed at regime survival and sanctions circumvention [1].
For a defender the practical change is narrow. Attributing an incident to one of six clusters still takes more than a blog post. What is usable now is the assumption underneath: an intrusion into a financial or crypto target from a DPRK-linked set should be read as funded work with an owner, and the same actor may be paying for its own espionage with the proceeds [4].
What to watch
- Whether Sekoia and Kudelski publish per-cluster malware families and infrastructure so defenders can map a live incident to one of the six.
- Whether other vendors adopt the six-cluster split or keep reporting under the Lazarus umbrella, which decides if cross-vendor correlation works at all.
- Any new sanctions designation naming a specific DPRK bureau, which would test whether the reorganization churn actually blunts designation.