• 2026.03.22 (Sun)
  • All articles
  • LOGIN
  • JOIN
Global Economic Times
fashionrunwayshow2026
  • Synthesis
  • World
  • Business
  • Industry
  • ICT
  • Distribution Economy
  • Well+Being
  • Travel
  • Eco-News
  • Education
  • Korean Wave News
  • Opinion
  • Arts&Culture
  • Sports
  • People & Life
    • International Student Report
    • With Ambassador
  • Column
    • Cho Kijo Column
    • Cherry Garden Story
    • Ko Yong-chul Column
    • Kim Seul-Ong Column
    • Lee Yeon-sil Column
  • Photo News
  • New Book Guide
MENU
 
Home > Synthesis

Cyber Synergy: Allegations of North Korean and Russian Hacking Groups Partnering Mark a New Threat Level

KO YONG-CHUL Reporter / Updated : 2025-11-25 11:50:31
  • -
  • +
  • Print


 (C) NK News


A recent analysis by a cybersecurity firm suggests a potentially unprecedented collaboration between state-sponsored cybercriminal organizations from North Korea and Russia, signaling a significant escalation in their cooperative efforts, possibly spurred by geopolitical alignment. The intelligence points to a dangerous convergence of tactics and infrastructure between North Korea's notorious Lazarus Group and Russia's Gamaredon, groups respectively linked to Pyongyang's Reconnaissance General Bureau (RGB) and Moscow's Federal Security Service (FSB). 

Evidence of Server and Tactic Sharing 

The findings, detailed in a report by the cyber defense company ZenDigital, reveal specific evidence suggesting that Lazarus and Gamaredon are sharing servers and hacking tactics.

ZenDigital analysts were tracking Gamaredon's use of Telegram channels to share command-and-control (C2) servers for distributing malware. During this monitoring, they identified that one of these C2 servers, utilized by Gamaredon, was also being actively used by the Lazarus Group. Further reinforcing the suspicion of shared infrastructure, a version of malware strongly associated with Lazarus was discovered operating on a server run by Gamaredon.

ZenDigital's analysts concluded that this dual usage points to a high probability that the two sophisticated groups are either sharing system resources directly collaborating on their campaigns. An alternative, though less likely scenario, is that one organization is intentionally and systematically mimicking the other.

Michal Salat, ZenDigital's Threat Intelligence Director, specifically suggested that Gamaredon, known for attacks against Ukrainian government networks, may be actively studying and incorporating the techniques of Lazarus, a group infamous for large-scale cryptocurrency theft and financial espionage. 

A Dangerous APT Collaboration 

The collaboration, if confirmed, represents a rare and alarming development in the landscape of state-backed hacking. Politico noted that it is uncommon for nation-state-linked Advanced Persistent Threat (APT) groups to distribute each other's malware.

Salat described the alleged partnership as "unprecedented," stating that he has never before seen an instance of such a high level of cooperation between two distinct APT groups from different nations, particularly in attacks that are typically sophisticated and long-term in nature.

This cyber-convergence can be interpreted as an expansion of the deepening military and political alliance between Russia and North Korea, an axis that has intensified following Russia's invasion of Ukraine.

"The sharing of critical C2 infrastructure not only reduces operational security costs for both groups but also creates a significant attribution challenge for Western intelligence and cybersecurity firms," notes one independent cybersecurity researcher. "It muddies the waters, allowing both nations a degree of plausible deniability while leveraging the combined expertise and resources."

Expanding Scope of Bilateral Cooperation 

The alleged cyber partnership follows months of increasing, tangible military and material cooperation between Moscow and Pyongyang.

North Korea has been accused of supplying Russia with a significant number of artillery shells and ballistic missiles for use in the war in Ukraine, a claim both countries deny despite mounting evidence. Conversely, Russia is suspected of providing North Korea with critical military technology and financial resources, potentially enabling Pyongyang's banned nuclear and missile programs.

Recent intelligence reports from Ukraine's Defense Intelligence Directorate (GUR) further indicate an escalation of this manpower exchange. The GUR recently claimed that North Korea is preparing to send thousands of its workers to Russia, ostensibly to assist in the production of self-destructing drones used on the frontlines. This suggests that the cooperation is moving beyond arms trade into shared industrial and military production efforts.

The reported cyber collaboration extends this military-industrial link into the domain of digital warfare and economic espionage. Lazarus, with its global reach and financial focus, and Gamaredon, with its geographical and governmental targeting, form a potent partnership. Lazarus's financial hacking prowess could potentially be used to fund or disrupt economies supporting Ukraine, while Gamaredon's tactical espionage could provide Russia with better intelligence on Ukrainian defense networks. 

Implications for Global Cyber Security 

The potential for synchronized or shared cyber operations between these two formidable groups raises the bar for international cybersecurity defense.

Increased Sophistication: By sharing best practices—Lazarus's stealthy financial techniques and Gamaredon's persistent governmental intrusion tactics—the combined threat is more sophisticated and harder to counter.
Attribution Challenges: The use of shared infrastructure complicates the crucial process of attribution, making it difficult for Western powers to confidently assign responsibility for an attack, which is essential for diplomatic and retaliatory measures.
Wider Target Scope: The focus of the alliance is likely to expand beyond Ukraine, potentially targeting Western governments, critical infrastructure, and financial institutions that are aligned against the Russian and North Korean interests.
The ZenDigital report serves as a critical warning that the deepening geopolitical ties between Russia and North Korea are not confined to traditional military matters but are now actively manifesting in the realm of Advanced Persistent Threats, demanding a renewed and unified defensive strategy from the international community.

[Copyright (c) Global Economic Times. All Rights Reserved.]

  • #globaleconomictimes
  • #micorea
  • #mykorea
  • #Lifeplaza
  • #nammidonganews
  • #singaporenewsk
  • #Samsung
  • #Daewoo
  • #Hyosung
  • #A
KO YONG-CHUL Reporter
KO YONG-CHUL Reporter
Reporter Page

Popular articles

  • Ko Sang-goo, President of World Federation of Korean Associations, Elected as First Private Sector Chair of World Korean Community Leaders Convention

  • Revised and Expanded Edition of ‘Failure of Negotiations with North Korea: Truth and Solutions’ Published

  • Commentary That Douses the Joy of Victory: A Twisted Perspective

I like it
Share
  • Facebook
  • X
  • Kakaotalk
  • LINE
  • BAND
  • NAVER
  • https://www.globaleconomictimes.kr/article/1065581320185675 Copy URL copied.
Comments >

Comments 0

Weekly Hot Issue

  • Coway Clinches Top Honor at "Water Taste Awards" for 7th Consecutive Year
  • HP Targets Korea as Strategic Hub for 'Edge AI' Expansion, Seeking Startup Partnerships
  • Pearl Abyss’s 'Crimson Desert' Shatters Records with 2 Million Copies Sold on Day One
  • "BTS Over Books?" Indian Academies Issue Emergency Notices as Students Plot Mass Absences for Comeback Live
  • Naver to Shut Down Men's Fashion Service 'MR.' to Launch Expanded AI-Driven Fashion Platform
  • JBNU and SKKU Researchers Achieve Breakthrough in "Dream Material" MXene, Setting New World Records in Performance

Most Viewed

1
An Open Letter to BTS On the Eve of a Historic Performance
2
From Industrial Capital to Tourism Mecca... Ulsan Makes a Bold Move with ‘Experiential Content’ in 2026
3
Ko Sang-goo, President of World Federation of Korean Associations, Elected as First Private Sector Chair of World Korean Community Leaders Convention
4
It is Time for BTS’s Fandom, ARMY, to Step Forward
5
Korean Stock Market Plunges: Circuit Breaker and Sidecar Triggered Amid Geopolitical Crisis
광고문의
임시1
임시3
임시2

Hot Issue

Vishay Unveils Ultra-Compact 0404 RGB LED with Independent Chip Control for Enhanced Color Precision

Coway Clinches Top Honor at "Water Taste Awards" for 7th Consecutive Year

AI Medical Ecosystem in Focus: KIMES 2026 Opens in Seoul as Global Healthcare Hub

Netanyahu Declares Decisive Blow to Iran’s Nuclear and Missile Programs, Signals Early End to War

Let’s recycle the old blankets in Jeju Island’s closet instead of incinerating them.

Global Economic Times
korocamia@naver.com
CEO : LEE YEON-SIL
Publisher : KO YONG-CHUL
Registration number : Seoul, A55681
Registration Date : 2024-10-24
Youth Protection Manager: KO YONG-CHUL
Singapore Headquarters
5A Woodlands Road #11-34 The Tennery. S'677728
Korean Branch
Phone : +82(0)10 4724 5264
#304, 6 Nonhyeon-ro 111-gil, Gangnam-gu, Seoul
Copyright © Global Economic Times All Rights Reserved
  • 에이펙2025
  • APEC2025가이드북TV
  • 독도는우리땅
Search
Category
  • All articles
  • Synthesis
  • World
  • Business
  • Industry
  • ICT
  • Distribution Economy
  • Well+Being
  • Travel
  • Eco-News
  • Education
  • Korean Wave News
  • Opinion
  • Arts&Culture
  • Sports
  • People & Life 
    • 전체
    • International Student Report
    • With Ambassador
  • Column 
    • 전체
    • Cho Kijo Column
    • Cherry Garden Story
    • Ko Yong-chul Column
    • Kim Seul-Ong Column
    • Lee Yeon-sil Column
  • Photo News
  • New Book Guide
  • Multicultural News
  • Jobs & Workers