Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: APT38, tracked as, Bluenoroff, cryptocurrency businesses, ATMs, Andariel, Hidden Cobra, Diamond Sleet, defense, IT organizations, Jade Sleet, cryptocurrency companies, Emerald Sleet, Kimsuky, REF9403, HIDDEN COBRA, ZINC, Labyrinth Chollima, Guardians of Peace, Stardust Chollima, cryptocurrency exchanges, billions in subseq, OperationTroy, Guardian of Peace, GOP, WHOis Team, Subgroup: Andariel, Onyx Sleet, PLUTONIUM, Sapphire Sleet, Quishing, Citrine Sleet, UNC4899, THALLIUM

Description

The DPRK cyber force, historically mapped to the Lazarus Group and known under monikers such as APT38 and Hidden Cobra, maintains an advanced threat capability that is both financially driven and politically motivated. In recent operations, investigators uncovered a distributed network of freelance “remote IT workers” who are recruited via AI‑driven target vetting, employ VPNs, and leverage popular freelancing platforms to access victim infrastructure undetected. Once inside, the adversary establishes persistence through scheduled tasks, COM objects, and legitimate‑looking executables while using PowerShell, rundll32, and DLL injection to deliver payloads. In parallel with their espionage portfolio – which includes collecting strategic data from governments, think tanks, and critical industries – they target cryptocurrency exchanges and online payment channels. The actor routinely deploys supply‑chain attacks that hijack npm modules such as BeaverTail or InvisibleFerret, allowing it to compromise well‑protected environments by masquerading as a trusted dependency. Their arsenal also incorporates spearphishing attachments (Word, PDF, ZIP) and malicious QR codes that redirect users to actor‑controlled domains. The threat actor’s modus operandi reflects a sophisticated blend of political motive and monetization: exfiltrated credentials facilitate long‑term compromise, while direct financial theft – particularly from crypto platforms – generates immediate illicit revenue. The repeated use of stolen certificates and fileless techniques indicates an ongoing investment in defensive evasion.”,

Goals & Targeting

Targeted Sectors

Financial services
Government
Critical infrastructure
Defense
Retail
Healthcare
Think tank
Media
Energy
Gaming
Education
Manufacturing
Nuclear
Entertainment
Transportation
Utilities

Targeted Countries / Regions

United States of America
Latvia
KP
US
KR
RU
JP

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 13 hours ago

Executive Summary

DPRK-linked actor, widely referenced as APT38 or Lazarus Group, orchestrates large‑scale financial theft against cryptocurrency exchanges, e‑commerce platforms, and software supply chains while simultaneously conducting espionage on governmental and critical infrastructure targets. The group blends sophisticated credential‑stealing, phishing/quishing campaigns, and file‑less PowerShell delivery with aggressive exploitation of cloud services and npm supply‑chain trust. CISA reports repeated breaches of high‑profile exchanges (e.g., Bybit) and consistent use of stolen certificates to sign malware, underscoring a dual motivation of economic gain and strategic espionage.

Enhanced Description

ATT&CK Techniques

Impact
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

URL 2 Domain 3 SHA-256 Hash 15

References

  1. unit42.paloaltonetworks.com — Cited by web research for: Bluenoroff
  2. www.elastic.co — Cited by web research for: REF9403
  3. www.huntress.com — Cited by web research for: HIDDEN COBRA
  4. attack.mitre.org — Cited by web research for: T1027
  5. www.group-ib.com — Cited by web research for: CVE-2016-0034
  6. attack.mitre.org — Cited by web research for: Entertainment

Intel Summary

40

Techniques

41

Tools

0

Campaigns

174

IOCs

0

Observed Data

13

Tactics

Tags

Financial Targeting

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
North Korea (KP)
Confidence
55%
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.