Also known as: APT38, Diamond Sleet, UNC4034, 0mid16B, Lazarus Group, ZINC, Selective Pisces, Bluenoroff, cryptocurrency businesses, ATMs, Andariel, Hidden Cobra, defense, IT organizations, Jade Sleet, cryptocurrency companies, Emerald Sleet, Kimsuky, such as Lockbit 2.0, Ryuk, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, APT28, VOLTZITE, HERMIT NEPTUNE, tracked as, such as, is a sophisticated, a separate entity, for follow-on operations, Sapphire Sleet, Citrine Sleet, Onyx Sleet, UNC4899, THALLIUM
TEMP.Hermit is an elusive group operating under multiple codenames—APT38, Diamond Sleet, Moonstone Sleet, Gleaming Pisces, Bluenoroff, and others—believed to be part of the North Korean Lazarus umbrella. Emerging at least as early as 2018, the actor has targeted a broad spectrum of victims, including government agencies, defense contractors, aerospace firms, critical infrastructure operators, financial institutions, and cryptocurrency businesses, across more than 30 countries. The group’s arsenal features highly sophisticated, custom-built malware families such as Duuzer‑style backdoor Trojans (Backdoor.Duuzer, CollectionRAT), ransomware variants (MAUI, LONEJOGGER, WannaCry 2.0), and cryptocurrency theft modules (BlueNoroff, RustBucket). Attack surfaces are breached via spear‑phishing emails with disguised shortcut files or forged HWP documents, watering‑hole infections of corporate web portals, zero‑day exploitation of vulnerabilities in Chrome, Apache Struts, and Apple software, and supply‑chain attacks against third‑party applications (3CX, Trading Technologies) and npm repositories. Persistence techniques include launch daemons and DLL hijacking on macOS, signed binaries with subverted certificates, and the use of legitimate VPN credentials for initial foothold. Lateral movement is facilitated through FRP masquerading as MsMpEng.exe and process injection into browsers, while command‑and‑control traffic is obfuscated using encrypted HTTPS sessions with cookie headers or dead‑drop GitHub repositories. Strategically, TEMP.Hermit blends intelligence gathering—targeting defense, aerospace, nuclear technology, and governmental knowledge—with financial exploitation. The actor routinely manipulates SWIFT messaging systems to create fraudulent transactions, siphons cryptocurrency from exchanges, and often deploys destructive ransomware as a revenue generator for the North Korean regime. Key capabilities include stealth malware delivery, sophisticated phishing, zero‑day exploitation, supply‑chain intrusion, data exfiltration, disk wiping, and financial fraud. The group’s operational tempo is rapid, with campaigns scaling from individual incidents to multi‑nation banking heists, demonstrating a high degree of coordination among DPRK units.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TEMP.Hermit, an alias of the North Korean Lazarus umbrella (APT38), is a sophisticated cyber‑espionage actor that targets defense, aerospace, financial, and critical infrastructure sectors worldwide. It deploys advanced phishing, watering‑hole, zero‑day, and supply‑chain techniques to install custom stealth malware, perform SWIFT fraud, steal cryptocurrency, and in some campaigns deliver destructive ransomware to fund operations. While espionage remains the primary objective, substantial efforts focus on monetization through financial theft.
Goals & Targeting
TEMP.Hermit seeks dual objectives: strategic intelligence acquisition on critical defense and aerospace technologies, and financial gain through SWIFT manipulation and cryptocurrency theft. Its targeting profile spans government bodies, critical infrastructure (energy, telecom, transportation), financial services, pharmaceuticals, education, aviation, maritime and IT service providers across at least thirty nations, reflecting a broad influence scope that aligns with North Korean geopolitical aims.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TEMP.Hermit typically initiates attacks with an engineered spear‑phishing email that delivers a malicious shortcut or document, followed by exploitation of either a zero‑day vulnerability or a watering‑hole to gain initial access. Once in the network, it establishes persistence through launch daemons and DLL hijacking on Windows/macOS, then expands via lateral movement tools such as FRP masquerading as system processes. The group frequently orchestrates SWIFT fraud by forging transaction messages, often after credential dumping or keylogging data has been exfiltrated. In parallel, it conducts cryptocurrency theft through malware like BlueNoroff and RustBucket, using cryptojacking backdoors to siphon funds into cross‑chain bridge wallets. Campaigns are rapid and adaptive; older operations (2018‑2020) involved large bank heists in the Pacific Rim, while recent incidents focus on supply‑chain compromise of popular software and targeted ransomware for monetization.
IOC Patterns
Recommended Actions
Suggested Tags
Sources
Confidence Assessment
The aggregation of vendor alerts, academic studies, and independent incident reports provides robust evidence that TEMP.Hermit is a sophisticated actor linked to the North Korean Lazarus umbrella. Confidence in its operational tactics and malware families is high; however, attribution granularity remains challenging due to tool-sharing among DPRK groups, incomplete coverage of all campaign periods, and gaps in publicly documented timestamps for early engagements.
No campaigns linked yet.
No observed data linked yet.
20
Techniques
54
Tools
0
Campaigns
39
IOCs
0
Observed Data
9
Tactics