logo

Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup

ID: 7f9b5d1e-d6bf-50b0-962b-8548fb5bab8a

STIX ID: report--7f9b5d1e-d6bf-50b0-962b-8548fb5bab8a

Feed Name: JPCERT Blog

Threat Score
85/100

Date Published: 2025-03-25

Date Updated: 2026-04-19

Author: 佐々木 勇人(Hayato Sasaki)

...
...

This JPCERT/CC blog post argues that the historical label “Lazarus” now describes a collection of multiple subgroups and task-force-like entities with overlapping tools and tactics; it explains why subgroup-level identification matters for targeted alerts, counter-operations, and deterrence. The report documents trends such as SNS-based targeting of engineers to deploy malicious npm/PyPI packages, reuse and overlap of RATs (Comebacker, PoolRAT/PondRAT), supply-chain activity, and examples of active campaigns (Moonstone Sleet, Gleaming/Citrine Sleet, Contagious Interview), and calls for dynamic classification to support effective defensive measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.