• 2026.06.27 (Sat)
  • All articles
  • LOGIN
  • JOIN
Global Economic Times
fashionrunwayshow2026
  • Synthesis
  • World
  • Business
  • Industry
  • ICT
  • Distribution Economy
  • Well+Being
  • Travel
  • Eco-News
  • Education
  • Korean Wave News
  • Opinion
  • Arts&Culture
  • Sports
  • People & Life
    • International Student Report
    • With Ambassador
  • Column
    • Cho Kijo Column
    • Cherry Garden Story
    • Ko Yong-chul Column
    • Kim Seul-Ong Column
    • Lee Yeon-sil Column
  • Photo News
  • New Book Guide
MENU
 
Home > Synthesis

Cyber Synergy: Allegations of North Korean and Russian Hacking Groups Partnering Mark a New Threat Level

KO YONG-CHUL Reporter / Updated : 2025-11-25 11:50:31
  • -
  • +
  • Print


 (C) NK News


A recent analysis by a cybersecurity firm suggests a potentially unprecedented collaboration between state-sponsored cybercriminal organizations from North Korea and Russia, signaling a significant escalation in their cooperative efforts, possibly spurred by geopolitical alignment. The intelligence points to a dangerous convergence of tactics and infrastructure between North Korea's notorious Lazarus Group and Russia's Gamaredon, groups respectively linked to Pyongyang's Reconnaissance General Bureau (RGB) and Moscow's Federal Security Service (FSB). 

Evidence of Server and Tactic Sharing 

The findings, detailed in a report by the cyber defense company ZenDigital, reveal specific evidence suggesting that Lazarus and Gamaredon are sharing servers and hacking tactics.

ZenDigital analysts were tracking Gamaredon's use of Telegram channels to share command-and-control (C2) servers for distributing malware. During this monitoring, they identified that one of these C2 servers, utilized by Gamaredon, was also being actively used by the Lazarus Group. Further reinforcing the suspicion of shared infrastructure, a version of malware strongly associated with Lazarus was discovered operating on a server run by Gamaredon.

ZenDigital's analysts concluded that this dual usage points to a high probability that the two sophisticated groups are either sharing system resources directly collaborating on their campaigns. An alternative, though less likely scenario, is that one organization is intentionally and systematically mimicking the other.

Michal Salat, ZenDigital's Threat Intelligence Director, specifically suggested that Gamaredon, known for attacks against Ukrainian government networks, may be actively studying and incorporating the techniques of Lazarus, a group infamous for large-scale cryptocurrency theft and financial espionage. 

A Dangerous APT Collaboration 

The collaboration, if confirmed, represents a rare and alarming development in the landscape of state-backed hacking. Politico noted that it is uncommon for nation-state-linked Advanced Persistent Threat (APT) groups to distribute each other's malware.

Salat described the alleged partnership as "unprecedented," stating that he has never before seen an instance of such a high level of cooperation between two distinct APT groups from different nations, particularly in attacks that are typically sophisticated and long-term in nature.

This cyber-convergence can be interpreted as an expansion of the deepening military and political alliance between Russia and North Korea, an axis that has intensified following Russia's invasion of Ukraine.

"The sharing of critical C2 infrastructure not only reduces operational security costs for both groups but also creates a significant attribution challenge for Western intelligence and cybersecurity firms," notes one independent cybersecurity researcher. "It muddies the waters, allowing both nations a degree of plausible deniability while leveraging the combined expertise and resources."

Expanding Scope of Bilateral Cooperation 

The alleged cyber partnership follows months of increasing, tangible military and material cooperation between Moscow and Pyongyang.

North Korea has been accused of supplying Russia with a significant number of artillery shells and ballistic missiles for use in the war in Ukraine, a claim both countries deny despite mounting evidence. Conversely, Russia is suspected of providing North Korea with critical military technology and financial resources, potentially enabling Pyongyang's banned nuclear and missile programs.

Recent intelligence reports from Ukraine's Defense Intelligence Directorate (GUR) further indicate an escalation of this manpower exchange. The GUR recently claimed that North Korea is preparing to send thousands of its workers to Russia, ostensibly to assist in the production of self-destructing drones used on the frontlines. This suggests that the cooperation is moving beyond arms trade into shared industrial and military production efforts.

The reported cyber collaboration extends this military-industrial link into the domain of digital warfare and economic espionage. Lazarus, with its global reach and financial focus, and Gamaredon, with its geographical and governmental targeting, form a potent partnership. Lazarus's financial hacking prowess could potentially be used to fund or disrupt economies supporting Ukraine, while Gamaredon's tactical espionage could provide Russia with better intelligence on Ukrainian defense networks. 

Implications for Global Cyber Security 

The potential for synchronized or shared cyber operations between these two formidable groups raises the bar for international cybersecurity defense.

Increased Sophistication: By sharing best practices—Lazarus's stealthy financial techniques and Gamaredon's persistent governmental intrusion tactics—the combined threat is more sophisticated and harder to counter.
Attribution Challenges: The use of shared infrastructure complicates the crucial process of attribution, making it difficult for Western powers to confidently assign responsibility for an attack, which is essential for diplomatic and retaliatory measures.
Wider Target Scope: The focus of the alliance is likely to expand beyond Ukraine, potentially targeting Western governments, critical infrastructure, and financial institutions that are aligned against the Russian and North Korean interests.
The ZenDigital report serves as a critical warning that the deepening geopolitical ties between Russia and North Korea are not confined to traditional military matters but are now actively manifesting in the realm of Advanced Persistent Threats, demanding a renewed and unified defensive strategy from the international community.

[Copyright (c) Global Economic Times. All Rights Reserved.]

  • #globaleconomictimes
  • #micorea
  • #mykorea
  • #Lifeplaza
  • #nammidonganews
  • #singaporenewsk
  • #Samsung
  • #Daewoo
  • #Hyosung
  • #A
KO YONG-CHUL Reporter
KO YONG-CHUL Reporter
Reporter Page

Popular articles

  • Our Embassy met on Friday, May 29, with the Kkottongnae brothers, who run a nursing home in the city of Caacupé, to learn about their main activities and future plans.

  • Ambassador Hyuk-Sang Sohn participated on May 26 in the signing ceremony of the Discussion Memorandum

  • Personal Interest Engraved on the Dollar: Witnessing the Regression of American Democracy

I like it
Share
  • Facebook
  • X
  • Kakaotalk
  • LINE
  • BAND
  • NAVER
  • https://www.globaleconomictimes.kr/article/1065581320185675 Copy URL copied.
Comments >

Comments 0

Weekly Hot Issue

  • BYD Unveils First Plug-in Hybrid ‘Sealion 6’ in Korea, Targeting Eco-Friendly Market at 37.5 Million Won 
  • Kia’s Strategic Pivot: Accelerating Electrification Through SDV, PBV, and EREV Innovation
  • Devastating Twin Earthquakes Strike Venezuela: Death Toll Rises Amid Humanitarian Crisis
  • Hyundai Motor Prioritizes "Customer Experience" Over Pricing: Aiming for Lifelong Loyalty with the New Avante
  • South Korea's Path to Round of 32 Grows Perilous Following Australia-Paraguay Draw
  • The True Face of Our Politics After Stripping Away the Mask of Fairness

Most Viewed

1
[In-depth Report] The Islamic ‘Halal Barrier’ Just Around the Corner… The Silent Screams of K-Beauty SMEs
2
Asking about the Future of ‘Hangeul City Ulsan’… Special Lecture by Novelist Kim Jin-myung to be Held
3
Embassy of Pakistan in Seoul Hosts Commemorative Event for the 150th Birth Anniversary of Muhammad Ali Jinnah
4
KOSPI Hits Historic 9,300 Milestone as Market Cap Surpasses 8,000 Trillion Won
5
Kim Yoon-ji Appointed as New President of KOCCA: “Leading the Global Expansion of K-Culture”
광고문의
임시1
임시3
임시2

Hot Issue

Devastating Twin Earthquakes Strike Venezuela: Death Toll Rises Amid Humanitarian Crisis

Political Debates Spark Over Semiconductor "Windfall" Redistribution

Google Play Hosts 'ChangGoo Alumni Day' to Accelerate Global Expansion for 760 Korean Startups

Government Slashes Petroleum Price Caps by 150 Won per Liter amid Easing Middle East Tensions

Fashion Runway Show 2026

Global Economic Times
korocamia@naver.com
CEO : LEE YEON-SIL
Publisher : KO YONG-CHUL
Registration number : Seoul, A55681
Registration Date : 2024-10-24
Youth Protection Manager: KO YONG-CHUL
Singapore Headquarters
5A Woodlands Road #11-34 The Tennery. S'677728
Korean Branch
Phone : +82(0)10 4724 5264
#304, 6 Nonhyeon-ro 111-gil, Gangnam-gu, Seoul
Copyright © Global Economic Times All Rights Reserved
  • 향기네무료급식
  • BCB부천방송
  • 반달곰 프로젝트
Search
Category
  • All articles
  • Synthesis
  • World
  • Business
  • Industry
  • ICT
  • Distribution Economy
  • Well+Being
  • Travel
  • Eco-News
  • Education
  • Korean Wave News
  • Opinion
  • Arts&Culture
  • Sports
  • People & Life 
    • 전체
    • International Student Report
    • With Ambassador
  • Column 
    • 전체
    • Cho Kijo Column
    • Cherry Garden Story
    • Ko Yong-chul Column
    • Kim Seul-Ong Column
    • Lee Yeon-sil Column
  • Photo News
  • New Book Guide
  • Multicultural News
  • Jobs & Workers