logo

Lazarus Group is No Longer Consider a Single APT Group, But Collection of Many Sub Groups

ID: d1c8dee6-7300-595f-b98d-ea8c86eaa02f

STIX ID: report--d1c8dee6-7300-595f-b98d-ea8c86eaa02f

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-03-31

Date Updated: 2026-04-21

Author: Balaji N

...
...

This analysis examines how the North Korean-linked Lazarus APT has fragmented into multiple specialized subgroups (e.g., Diamond Sleet, Citrine Sleet, Moonstone Sleet) that share overlapping tactics, techniques, and procedures—complicating attribution—and details campaigns targeting cryptocurrency businesses (Operation Dreamjob, AppleJeus), use of malicious packages and social engineering, and implications for targeted alerts, countermeasures, and the balance between soft and hard attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.