Post

Beyond Lazarus How North Korea Organizes Its Cyber Operations

Beyond Lazarus How North Korea Organizes Its Cyber Operations

Beyond Lazarus: How North Korea Organizes Its Cyber Operations

The DPRK built its cyber capability as a deliberate extension of its asymmetric deterrence doctrine, treating cyber operations as a cheap, deniable “all-purpose sword” alongside nuclear weapons to ensure regime survival against better-resourced adversaries and circumvent international sanctions. From roughly 2014 onward, cyber operations evolved from espionage and sabotage into a load-bearing revenue stream, including bank heists, ransomware, and cryptocurrency theft, financing the very weapons programs that international sanctions were designed to constrain.

Even as the GRIB (ex-RGB) and NIA (ex-MSS) consistently lead DPRK cyber offensive operations, the units and bureaus beneath them are subject to constant reorganization. This is a deliberate control mechanism that keeps agencies competing for Kim Jong-un’s favor, prevents consolidation of independent power, and complicates the attribution and sanctions-designation efforts of foreign governments. DPRK offensive cyber operations are distributed across APT clusters, with the former Lazarus umbrella now decomposed by Sekoia and Kudelski Security into six distinct sub-clusters, nearly all of which conduct lucrative operations, whether as their primary mandate or to self-fund espionage and sabotage campaigns.

These APT intrusion sets are complemented by thousands of IT workers operating under false identities worldwide. They serve a dual function: remitting salaries to the regime and leveraging their insider access within contracted organizations to conduct further operations, with proceeds laundered through centralized exchanges, decentralized exchanges (DEXs), and P2P platforms. The DPRK has also constructed a complex network of educational and private intermediaries to enable its cyber operations, spanning academic institutions that both train operatives and function as operational nodes.

Read full article

This post is licensed under CC BY 4.0 by the author.