Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TEMP.Hermit

Also known as: APT38, Diamond Sleet, UNC4034, 0mid16B, Lazarus Group, ZINC, Selective Pisces, Bluenoroff, cryptocurrency businesses, ATMs, Andariel, Hidden Cobra, defense, IT organizations, Jade Sleet, cryptocurrency companies, Emerald Sleet, Kimsuky, such as Lockbit 2.0, Ryuk, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, APT28, VOLTZITE, HERMIT NEPTUNE, tracked as, such as, is a sophisticated, a separate entity, for follow-on operations, Sapphire Sleet, Citrine Sleet, Onyx Sleet, UNC4899, THALLIUM

Description

TEMP.Hermit is an elusive group operating under multiple codenames—APT38, Diamond Sleet, Moonstone Sleet, Gleaming Pisces, Bluenoroff, and others—believed to be part of the North Korean Lazarus umbrella. Emerging at least as early as 2018, the actor has targeted a broad spectrum of victims, including government agencies, defense contractors, aerospace firms, critical infrastructure operators, financial institutions, and cryptocurrency businesses, across more than 30 countries. The group’s arsenal features highly sophisticated, custom-built malware families such as Duuzer‑style backdoor Trojans (Backdoor.Duuzer, CollectionRAT), ransomware variants (MAUI, LONEJOGGER, WannaCry 2.0), and cryptocurrency theft modules (BlueNoroff, RustBucket). Attack surfaces are breached via spear‑phishing emails with disguised shortcut files or forged HWP documents, watering‑hole infections of corporate web portals, zero‑day exploitation of vulnerabilities in Chrome, Apache Struts, and Apple software, and supply‑chain attacks against third‑party applications (3CX, Trading Technologies) and npm repositories. Persistence techniques include launch daemons and DLL hijacking on macOS, signed binaries with subverted certificates, and the use of legitimate VPN credentials for initial foothold. Lateral movement is facilitated through FRP masquerading as MsMpEng.exe and process injection into browsers, while command‑and‑control traffic is obfuscated using encrypted HTTPS sessions with cookie headers or dead‑drop GitHub repositories. Strategically, TEMP.Hermit blends intelligence gathering—targeting defense, aerospace, nuclear technology, and governmental knowledge—with financial exploitation. The actor routinely manipulates SWIFT messaging systems to create fraudulent transactions, siphons cryptocurrency from exchanges, and often deploys destructive ransomware as a revenue generator for the North Korean regime. Key capabilities include stealth malware delivery, sophisticated phishing, zero‑day exploitation, supply‑chain intrusion, data exfiltration, disk wiping, and financial fraud. The group’s operational tempo is rapid, with campaigns scaling from individual incidents to multi‑nation banking heists, demonstrating a high degree of coordination among DPRK units.

Goals & Targeting

Targeted Sectors

Aerospace & defense
Financial services
Government
Defense
Telecommunications
Healthcare
Education
Manufacturing
Media
Energy
Critical infrastructure
Pharmaceutical
Non profit
Aerospace
Aviation
Hospitality
Nuclear
Entertainment
Think tank
Retail
Information technology
Transportation
Mining
Chemical
Gaming
Legal services
Oil gas
Maritime
Construction
Utilities

Targeted Countries / Regions

KP
US
CN
JP
RU
KR
IR
TW
VN
IL
GB
AU
SA
PK
AE
UA
IN
SG
DE
BY
TR
MX
ES
PL
CA
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 16 chunks · 1 week ago

Executive Summary

TEMP.Hermit, an alias of the North Korean Lazarus umbrella (APT38), is a sophisticated cyber‑espionage actor that targets defense, aerospace, financial, and critical infrastructure sectors worldwide. It deploys advanced phishing, watering‑hole, zero‑day, and supply‑chain techniques to install custom stealth malware, perform SWIFT fraud, steal cryptocurrency, and in some campaigns deliver destructive ransomware to fund operations. While espionage remains the primary objective, substantial efforts focus on monetization through financial theft.

Goals & Targeting

TEMP.Hermit seeks dual objectives: strategic intelligence acquisition on critical defense and aerospace technologies, and financial gain through SWIFT manipulation and cryptocurrency theft. Its targeting profile spans government bodies, critical infrastructure (energy, telecom, transportation), financial services, pharmaceuticals, education, aviation, maritime and IT service providers across at least thirty nations, reflecting a broad influence scope that aligns with North Korean geopolitical aims.

Enhanced Description

Key Capabilities

  • Advanced stealth malware
  • Spear‑phishing campaigns using disguised shortcut files and forged documents
  • Watering‑hole infections targeting corporate websites
  • Zero‑day vulnerability exploitation (e.g., Chrome CVE‑2022‑0609, Apache Struts)
  • Custom keylogging implants
  • Backdoor Trojans for remote access (Duuzer, Backdoor.Duuzer, CollectionRAT, PoolRAT)
  • Destructive ransomware deployment (MAUI, LONEJOGGER, WannaCry variants)
  • Cryptocurrency theft via macOS BlueNoroff and RustBucket modules
  • Supply‑chain attacks against third‑party software (3CX, Trading Technologies, npm packages)
  • SWIFT fraud through forged transaction messages
  • PERSISTENCE mechanisms: launch daemons, DLL hijacking, signed binaries
  • C2 channels using HTTPS with cookie headers, GitHub dead‑drops, encrypted traffic
  • Lateral movement via FRP and masqueraded system processes
  • Data exfiltration and disk wiping to remove evidence

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Discovery
Privilege Escalation
Resource Development
Command and Control
Defense Evasion
Collection
Exfiltration
Impact

ATT&CK Techniques

T1566
T1566.001
T1189
T1203
T1071.001
T1105
T1041
T1059
T1609
T1070.004
T1485
T1217
T1543.004
T1678
T1573.001
T1546.016
T1657
T1574.001
T1559
T1027
T1055
T1090
T1195
T1204
T1003

Software / Tooling

TEMP.Hermit
APT38
Labyrinth Chollima
UNC4034
Temp.Firework
Kimsuky
Bureau 121
Bureau 325
Hidden Cobra
Storm-0501 Group
AppleJeus
RustBucket
Duuzer
Backdoor.Duuzer
BlueNoroff
PondRAT
POOLRAT
OdicLoader
Comebacker
CollectionRAT
3CX
ICONICSTEALER
VEILEDSIGNAL
TAXHAUL
SigFlip
DAVESHELL
X_TRADER
Setup.exe
FRP
LogCabin
MAUI
LONEJOGGER
PENCILDOWN
ROCKHATCH
HANGMAN.V2
CAKETEARS
FULLHOUSE.DOORED
WannaCry 2.0
FudModule
Moonstone Sleet
Citrine Sleet
Gleaming Pisces
VOLGMER
PEACHPIT

Campaigns & Victims

TEMP.Hermit typically initiates attacks with an engineered spear‑phishing email that delivers a malicious shortcut or document, followed by exploitation of either a zero‑day vulnerability or a watering‑hole to gain initial access. Once in the network, it establishes persistence through launch daemons and DLL hijacking on Windows/macOS, then expands via lateral movement tools such as FRP masquerading as system processes. The group frequently orchestrates SWIFT fraud by forging transaction messages, often after credential dumping or keylogging data has been exfiltrated. In parallel, it conducts cryptocurrency theft through malware like BlueNoroff and RustBucket, using cryptojacking backdoors to siphon funds into cross‑chain bridge wallets. Campaigns are rapid and adaptive; older operations (2018‑2020) involved large bank heists in the Pacific Rim, while recent incidents focus on supply‑chain compromise of popular software and targeted ransomware for monetization.

IOC Patterns

  • Watering‑hole infection vectors
  • Spear-phishing with disguised shortcut files
  • Drive‑by compromise via hidden iframe
  • Automatic download of additional malicious payloads after initial compromise
  • Zero-day vulnerability exploitation
  • Keylogger deployment
  • Remote access Trojans indicators
  • Persistence mechanisms (launch daemons, DLL hijacking)
  • C2 traffic encrypted or using cookie headers on HTTPS
  • Dead-drop C&C on GitHub repositories
  • Process injection into browsers
  • Masqueraded system binaries (e.g., MsMpEng.exe)
  • Log deletion and disk wiping indicators
  • Disguised archive files containing malicious payloads
  • Supply‑chain attack indicators (3CX, npm packages)
  • Cryptocurrency wallet address patterns
  • SWIFT message alteration indicators
  • Cross-chain bridge domain names

Recommended Actions

  • Deploy advanced endpoint protection with behavioral analytics to detect ransomware and custom stealth malware.
  • Strengthen email security using spear-phishing filters, attachment sandboxing, and user training focused on shortcut file disguises and HWP document attacks.
  • Keep all operating systems, browsers (Chrome – CVE‑2022‑0609), and critical applications fully patched to close zero‑day vectors.
  • Segment networks, enforce least privilege, and monitor privileged account usage to limit lateral movement; restrict VPN credential use.
  • Implement robust logging of SWIFT transaction integrity and alert on anomalous message alterations or unauthorized access.
  • Enforce code-signing validation and block unsigned launch daemons or DLL hijacking attempts; require trusted certificates.
  • Deploy supply-chain protection controls for third‑party software dependencies (3CX, Trading Technologies, npm, PyPI) including integrity checks and vendor verification.
  • Block known malicious domains/IPs tied to GitHub dead‑drops and other C2 infrastructure through firewall/EDR policies.
  • Monitor file deletion, disk wiping, and unexpected process injection as indicators of destructive activity; correlate with user account changes.
  • Adopt multi‑factor authentication for all critical systems, especially those handling financial data or SWIFT operations.
  • Track cryptocurrency wallet addresses associated with known bad actors, enforce AML controls against crypto transfers, and block exchanges when necessary.
  • Continuously hunt for the IOC patterns listed in our profile, leveraging EDR and SIEM analytics.

Suggested Tags

North Korea
APT38
Lazarus Group
TEMP.Hermit
Cyber Espionage
Ransomware
Financial Theft
SWIFT Heist
Cryptocurrency Theft
Watering-hole Attack
Spear Phishing
Supply Chain Compromise
Zero-Day Exploitation
Keylogger Malware
Remote Access Tools
Credential Theft
Defense Intelligence Targeting
Critical Infrastructure Targeting
Data Destruction
Cross-chain Bridge Abuse
Malware Signing Spoofing
Code Injection
Persistence
Cryptojacking

Sources

Confidence Assessment

The aggregation of vendor alerts, academic studies, and independent incident reports provides robust evidence that TEMP.Hermit is a sophisticated actor linked to the North Korean Lazarus umbrella. Confidence in its operational tactics and malware families is high; however, attribution granularity remains challenging due to tool-sharing among DPRK groups, incomplete coverage of all campaign periods, and gaps in publicly documented timestamps for early engagements.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 2 SHA-256 Hash 17 IPv4 Address 1

References

  1. www.huntress.com — Cited by web research for: Selective Pisces
  2. unit42.paloaltonetworks.com — Cited by web research for: Bluenoroff
  3. cloud.google.com — Cited by web research for: such as Lockbit 2.0
  4. attack.mitre.org — Cited by web research for: Sandworm Team
  5. attack.mitre.org — Cited by web research for: T1071
  6. apt.etda.or.th — Cited by web research for: Phishing emails
  7. blogs.jpcert.or.jp — Cited by web research for: PLAY

Intel Summary

20

Techniques

54

Tools

0

Campaigns

39

IOCs

0

Observed Data

9

Tactics

Tags

APT
Financial Targeting
espionage
financial-fraud
aerospace-defense
North Korea
APT38
Lazarus Group
TEMP.Hermit
Cyber Espionage
Ransomware
Financial Theft
SWIFT Heist
Cryptocurrency Theft
Watering-hole Attack
Spear Phishing
Supply Chain Compromise
Zero-Day Exploitation
Keylogger Malware
Remote Access Tools
Credential Theft
Defense Intelligence Targeting
Critical Infrastructure Targeting
Data Destruction
Cross-chain Bridge Abuse
Malware Signing Spoofing
Code Injection
Persistence
Cryptojacking

Details

MITRE ID
APT38
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
K
Confidence
50%
Added
Jul 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.