On September 7, 2026, researchers from Kudelski Security and Sekoia dropped a joint report on North Korean cyber operations. Instead of lumping everything under the familiar Lazarus Group label, they broke down the activity into six distinct clusters. The takeaway: North Korea’s cyber game is way broader than the usual “Lazarus” umbrella.

Six Clusters, Not Just One ‘Lazarus’

The team mapped out campaigns by goals and connections, splitting up the monolithic Lazarus concept into six stable clusters. They focused on cyber espionage, revenue generation, fake IT workers, and sprawling support networks. This approach shows how different tactics and objectives all plug into a single, complex ecosystem of North Korean ops.

Why This Matters for Attribution and Defense

Moving from a “one-size-fits-all” Lazarus view to clusters lets defenders get a sharper read on motivation and tools behind each branch—making it easier to build targeted defenses and incident response. When you can separate activity by clear traits, it’s way simpler to match incident artifacts and figure out which cluster’s playbook you’re up against.

Research Context

This study pulls together North Korea’s wide-ranging cyber activity—from profit-driven hacks to hardcore espionage and the infrastructure propping it all up. Researchers conclude that what’s called Lazarus is actually a more complicated structure, with each cluster playing its own role in the bigger picture.