Also known as: APT38, tracked as, Bluenoroff, cryptocurrency businesses, ATMs, Andariel, Hidden Cobra, Diamond Sleet, defense, IT organizations, Jade Sleet, cryptocurrency companies, Emerald Sleet, Kimsuky, REF9403, HIDDEN COBRA, ZINC, Labyrinth Chollima, Guardians of Peace, Stardust Chollima, cryptocurrency exchanges, billions in subseq, OperationTroy, Guardian of Peace, GOP, WHOis Team, Subgroup: Andariel, Onyx Sleet, PLUTONIUM, Sapphire Sleet, Quishing, Citrine Sleet, UNC4899, THALLIUM
The DPRK cyber force, historically mapped to the Lazarus Group and known under monikers such as APT38 and Hidden Cobra, maintains an advanced threat capability that is both financially driven and politically motivated. In recent operations, investigators uncovered a distributed network of freelance “remote IT workers” who are recruited via AI‑driven target vetting, employ VPNs, and leverage popular freelancing platforms to access victim infrastructure undetected. Once inside, the adversary establishes persistence through scheduled tasks, COM objects, and legitimate‑looking executables while using PowerShell, rundll32, and DLL injection to deliver payloads. In parallel with their espionage portfolio – which includes collecting strategic data from governments, think tanks, and critical industries – they target cryptocurrency exchanges and online payment channels. The actor routinely deploys supply‑chain attacks that hijack npm modules such as BeaverTail or InvisibleFerret, allowing it to compromise well‑protected environments by masquerading as a trusted dependency. Their arsenal also incorporates spearphishing attachments (Word, PDF, ZIP) and malicious QR codes that redirect users to actor‑controlled domains. The threat actor’s modus operandi reflects a sophisticated blend of political motive and monetization: exfiltrated credentials facilitate long‑term compromise, while direct financial theft – particularly from crypto platforms – generates immediate illicit revenue. The repeated use of stolen certificates and fileless techniques indicates an ongoing investment in defensive evasion.”,
Targeted Sectors
Targeted Countries / Regions
Executive Summary
DPRK-linked actor, widely referenced as APT38 or Lazarus Group, orchestrates large‑scale financial theft against cryptocurrency exchanges, e‑commerce platforms, and software supply chains while simultaneously conducting espionage on governmental and critical infrastructure targets. The group blends sophisticated credential‑stealing, phishing/quishing campaigns, and file‑less PowerShell delivery with aggressive exploitation of cloud services and npm supply‑chain trust. CISA reports repeated breaches of high‑profile exchanges (e.g., Bybit) and consistent use of stolen certificates to sign malware, underscoring a dual motivation of economic gain and strategic espionage.
Enhanced Description
No campaigns linked yet.
No observed data linked yet.
40
Techniques
41
Tools
0
Campaigns
174
IOCs
0
Observed Data
13
Tactics