APT38 — APT Profile
APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile ; some of their attacks have been destructive. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM
IntelFusions coverage (6)
- Hijacked Rust package backdoors any machine that builds it 2026-08-20 · Nation-State
- State hackers now log in instead of dropping malware 2026-08-20 · Nation-State
- Attackers weaponize most public exploits within 48 hours 2026-08-03 · Vulnerabilities
- China-linked groups drive most state-backed attacks on tech firms 2026-06-10 · Nation-State
- Lazarus Group's LinkedIn Recruiting Scam Deploys Cross-Platform Stealer Chain Leading to Tsunami Framework and Tor C2 2026-02-16 · Nation-State
- Lazarus Group (APT38): North Korea's Most Prolific Cyber Threat Actor Targets Banks, Crypto, and Critical Infrastructure 2026-02-16 · Nation-State
Tools & malware
- DarkComet Remote Access Trojan
- ECCENTRICBANDWAGON Backdoor
- HOPLIGHT Backdoor
- KillDisk Wiper
- Mimikatz Credential Harvesting
- Net Network Reconnaissance
Vendor research
- NICKEL GLADSTONE Threat Profile SecureWorks
- BlueNoroff introduces new methods bypassing MoTW Kaspersky
- The BlueNoroff cryptocurrency hunt is still on Kaspersky
- How Microsoft names threat actors Microsoft
- APT38: Un-usual Suspects FireEye
- NICKEL GLADSTONE Threat Profile Secureworks
- Meet CrowdStrike’s Adversary of the Month for April: STARDUST CHOLLIMA Crowdstrike
- Lazarus Under the Hood Kaspersky
- CrowdStrike 2021 Global Threat Report Crowdstrike
- Three North Korean Military Hackers Indicted in Wide-Ranging Scheme to Commit Cyberattacks and Financial Crimes Across the Globe DOJ
- FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks CISA AA
Countries linked to this actor
- North Korea origin
- Japan targets
- Kuwait targets
- Philippines targets
- Bangladesh targets
- Spain targets
- Tanzania targets
- Malta targets
- Peru targets
- Kenya targets