APTアクターの分類“中毒” ―Lazarus のサブグループ分類に見るアトリビューションの実務的課題―

2025-01-20 JPCERT APT Actor Classification Overload: Practical Attribution Challenges in Classifying Lazarus Subgroups

https://blogs.jpcert.or.jp/ja/2025/01/grouping-lazarus-subgroups.html

Thumbnail for APTアクターの分類“中毒” ―Lazarus のサブグループ分類に見るアトリビューションの実務的課題―

JPCERT/CC discusses the practical attribution problem created by treating Lazarus as a single threat actor label rather than a collection of DPRK-aligned subgroups. The report argues that subgroup-level classification matters for incident response because different Lazarus units can use distinct malware, infrastructure, targeting patterns, and operational goals. It is most useful as analytic context for CTI teams comparing Lazarus-linked activity across campaigns instead of assigning every intrusion to one broad actor name.

Related Actors

Related Reports

« Back