Beyond Lazarus: Organization of DPRK cyber capabilities

Beyond Lazarus: Organization of DPRK cyber capabilities

The article explains how the DPRK has built cyber operations into a core state instrument for espionage, sanctions evasion, and revenue generation, backed by institutions such as the GRIB, NIA, and KWP. It also details the role of DPRK threat clusters and fake IT workers in funding weapons programs, with activity spanning cryptocurrency theft, laundering networks, and overseas relay infrastructure. #DPRK #GRIB #NIA #KWP #Lazarus #Kimsuky #Andariel #Reaper #Bybit #HuioneGroup

Keypoints

  • The DPRK uses cyber operations as a strategic tool for regime survival, sanctions evasion, intelligence collection, and revenue generation.
  • Offensive cyber capabilities are concentrated mainly in the GRIB, with additional roles played by the NIA and the KWP.
  • North Korean threat activity has evolved from early DDoS and destructive attacks into a mix of espionage, theft, ransomware, and crypto heists.
  • The Lazarus umbrella has been broken into multiple sub-clusters, including TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima.
  • Fake IT workers are a major DPRK revenue channel, using false identities, overseas placements, and proxy infrastructure to earn and launder funds.
  • China and Russia serve as important enabling environments through universities, relay networks, front companies, and laundering channels.
  • Cryptocurrency theft and laundering remain central to DPRK operations, with examples including Bybit, Munchables, OnyxDAO, and Huione-linked laundering.

MITRE Techniques

  • [T1059 ] Command and Scripting Interpreter – DPRK operators use scripted tooling and operational workflows to conduct intrusions and manage activities (‘conduct operations from abroad’).
  • [T1071 ] Application Layer Protocol – Fake IT workers and operators rely on chat platforms and online services for coordination (‘Chat platforms, mainly Slack and IP Messenger (IPmsg)’).
  • [T1090 ] Proxy – The article describes proxy infrastructure and relay networks used to hide origin and route activity (‘a proxy operated by Ryonbong and marked as “RB”‘).
  • [T1584 ] Compromise Infrastructure – DPRK actors use front companies, hotels, and overseas hubs as operational bases (‘offices, hotels, or front companies staffed or frequented by DPRK operatives’).
  • [T1036 ] Masquerading – Fake IT workers conceal identity and location to gain employment and access (‘systematically obfuscating their location and identity’).
  • [T1548 ] Abuse Elevation Control Mechanism – The regime leverages sanctioned entities and covered roles to extend access and capabilities (‘access to the function is far from open to the general population’).
  • [T1567 ] Exfiltration to Cloud Storage / Web Service – Stolen crypto and funds are moved through exchanges and P2P platforms (‘Converting stolen assets via centralized exchanges or OTC trades’).
  • [T1105 ] Ingress Tool Transfer – Operators and workers use compromised infrastructure and shared nodes to move tools and support operations (‘share the same VPN exit nodes’).
  • [T1486 ] Data Encrypted for Impact – Wiper and destructive operations are referenced, including the use of disk-wipe tools as anti-forensics (‘leveraged disk-wipe techniques (KillDisk)’).
  • [T1490 ] Inhibit System Recovery – Wiper activity and destructive tooling are used to damage systems and hinder recovery (‘wiper components’).
  • [T1561 ] Disk Wipe – The article explicitly mentions disk-wipe techniques used in destructive campaigns (‘KillDisk’).
  • [T1078 ] Valid Accounts – Fake IT workers obtain legitimate-looking access through employment and onboarded roles (‘secure contracts in the IT sector’).
  • [T1005 ] Data from Local System – Workers query internal corporate documentation while embedded in companies (‘queried internal corporate documentation’).

Indicators of Compromise

  • [IP addresses] IP exit nodes used by DPRK fake IT workers and campaign overlap – 23.237.102.130, 45.86.208.162, and 66.118.255.35
  • [IP addresses] Additional proxy/relay nodes referenced in annex data – 37.120.154.98, 70.32.3.15, and other 11 items
  • [Organization names] DPRK-linked laundering and operational entities – Huione Group, Ryonbong
  • [Organization names] Front companies and supporting businesses – Chosun Expo, Chinyong Information Technology Cooperation Company
  • [Malware / tool names] DPRK-associated malicious tooling and ransomware – Maui, H0lyGh0st, FakePenny, KillDisk
  • [Threat clusters / group names] DPRK intrusion sets and sub-clusters – Kimsuky, Andariel, CryptoCore, Jade Sleet, Moonstone Sleet, Famous Chollima
  • [University / host institutions] Educational entities used in talent pipelines and logs – Shanghai University of Electric Power, Kim Chaek University of Technology
  • [Financial / crypto targets] Victim organizations and theft contexts – Bybit, Munchables, OnyxDAO, Exclusible Penthouse


Read more: https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities