Diamond Sleet, also known as Pompilus, is a North Korean state-sponsored threat actor associated with the broader Lazarus cluster. It is referenced as a Lazarus subgroup and has been linked to use of the Comebacker backdoor and loader, a malware family associated with Lazarus operations. Public reporting in the supplied material does not establish a complete independent profile for Pompilus beyond this tooling association, and attribution in the referenced ransomware activity remains unresolved at the subgroup level. The available evidence supports describing Pompilus as part of North Korea’s offensive cyber ecosystem rather than as a distinct financially motivated criminal group. High-confidence details on its specific victimology, preferred sectors, geographic targeting, and full operational scope are currently not available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North Korea-linked activity cluster associated (in prior reporting) with the Comebacker backdoor; mentioned here to note tooling overlap complicating sub-group attribution within Lazarus-linked operations.
North Korea-linked activity cluster associated (in prior reporting) with the Comebacker backdoor; mentioned here to note tool overlap within Lazarus-attributed operations.
Named Lazarus-linked activity cluster referenced as previously associated with the Comebacker backdoor.
North Korea-aligned cluster associated (in prior reporting) with the Comebacker backdoor/loader; mentioned here to highlight tooling overlap complicating attribution among Lazarus sub-groups.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.