Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup

2025-03-25 JPCERT

https://blogs.jpcert.or.jp/en/2025/03/classifying-lazaruss-subgroup.html

Thumbnail for Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup

JPCERT/CC argues that Lazarus should be treated as a collection of overlapping subgroups rather than a single actor label, because shared tooling, infrastructure, and social-engineering tradecraft now blur campaign and group boundaries. The article explains why subgroup-level attribution matters for Japan: it enables more precise sector alerts, supports longer-term countermeasures and potential counter-operations, and signals defender visibility to the operators behind DPRK-linked activity. It highlights Moonstone Sleet, Gleaming Pisces/Citrine Sleet, and Contagious Interview as examples where similar LinkedIn/SNS lures, PyPI/npm packages, RAT lineages, and cryptocurrency or IT-worker objectives complicate classification. The report is important for DPRK tracking because it maps Lazarus-related labels, campaigns, and aliases while cautioning against overconfident attribution when TTPs overlap across subgroups.

Related Actors

Related Reports

2025-04-24 • 50% Match
#ThreatNeedle #LPEClient #SIGNBT #AGAMEMNON #Lazarus #Innorix #SyncHole #CrossEX #T1027.013 #T1082 #T1140 #T1071.001 #T1083 #T1057 #T1583.003 #T1583.001 #T1105 #T1620 #T1574.002 #T1135 #T1573.001 #T1190 #T1189 #T1049 #T1573.002 #T1016 #T1087.001 #T1218.011 #T1584.001 #T1574.001 #T1564.004 #T1027.009 #T1569.002 #T1543.003 #T1087.002 #T1570 #T1608.004 #T1547.005 #T1007
Shares tag: Lazarus • Published within a month
« Back