FORENSIA

THREAT_ACTOR · G0082

APT38

Also known as: APT38, NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM

Profile

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile; some of their attacks have been destructive. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

MITRE ATT&CK ↗

Techniques

56 ATT&CK techniques attributed to this actor.

T1005 Data from Local SystemT1027.002 Software PackingT1033 System Owner/User DiscoveryT1036.003 Rename Legitimate UtilitiesT1036.006 Space after FilenameT1049 System Network Connections DiscoveryT1053.003 CronT1053.005 Scheduled TaskT1055 Process InjectionT1056.001 KeyloggingT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1070.004 File DeletionT1070.006 TimestompT1071.001 Web ProtocolsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1105 Ingress Tool TransferT1106 Native APIT1110 Brute ForceT1112 Modify RegistryT1115 Clipboard DataT1135 Network Share DiscoveryT1140 Deobfuscate/Decode Files or InformationT1189 Drive-by CompromiseT1204.001 Malicious LinkT1204.002 Malicious FileT1217 Browser Information DiscoveryT1218.001 Compiled HTML FileT1218.005 MshtaT1218.007 MsiexecT1218.011 Rundll32T1480.002 Mutual ExclusionT1485 Data DestructionT1486 Data Encrypted for ImpactT1505.003 Web ShellT1518.001 Security Software DiscoveryT1529 System Shutdown/RebootT1543.003 Windows ServiceT1548.002 Bypass User Account ControlT1553.005 Mark-of-the-Web BypassT1561.002 Disk Structure WipeT1565.001 Stored Data ManipulationT1565.002 Transmitted Data ManipulationT1565.003 Runtime Data ManipulationT1566.001 Spearphishing AttachmentT1569.002 Service ExecutionT1583.001 DomainsT1588.002 ToolT1685 Disable or Modify ToolsT1685.005 Clear Windows Event LogsT1686 Disable or Modify System FirewallT1686.002 Network Device FirewallT1690 Prevent Command History Logging

Software

6 malware/tools attributed to this actor.

MimikatzNetDarkCometHOPLIGHTECCENTRICBANDWAGONKillDisk

Related corpus activity

10,285 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to APT38.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-2492cve852
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2020-22658cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-23304cve852
cve-2021-4045cve851
cve-2020-22653cve852
cve-2022-47945cve851
cve-2025-34117cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,285.