Lazarus Group is No Longer Consider a Single APT Group, But Collection of Many Sub Groups
ID: d1c8dee6-7300-595f-b98d-ea8c86eaa02f
STIX ID: report--d1c8dee6-7300-595f-b98d-ea8c86eaa02f
Feed Name: cybersecurityNews.com
This analysis examines how the North Korean-linked Lazarus APT has fragmented into multiple specialized subgroups (e.g., Diamond Sleet, Citrine Sleet, Moonstone Sleet) that share overlapping tactics, techniques, and procedures—complicating attribution—and details campaigns targeting cryptocurrency businesses (Operation Dreamjob, AppleJeus), use of malicious packages and social engineering, and implications for targeted alerts, countermeasures, and the balance between soft and hard attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
