Also known as: NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM, APT38, ElectricFish, the Lazarus Group, TraderTraitor, Stardust Cholima, TA444, tracked as, Hidden Cobra, GhostCall, GhostHire, targeting executives, the North Korea, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, BlueNoroff
APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.(Citation: CISA AA20-239A BeagleBoyz August 2020) Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext (Citation: FireEye APT38 Oct 2018) and Banco de Chile (Citation: FireEye APT38 Oct 2018); some of their attacks have been destructive.(Citation: CISA AA20-239A BeagleBoyz August 2020)(Citation: FireEye APT38 Oct 2018)(Citation: DOJ North Korea Indictment Feb 2021)(Citation: Kaspersky Lazarus Under The Hood Blog 2017) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT38, also known as NICKEL GLADSTONE, BeagleBoyz, and Bluenoroff, is a North Korean state-sponsored cyber threat group primarily targeting financial institutions for financial gain. They are known for sophisticated attacks including bank heists, SWIFT system exploitation, and destructive operations against banks, casinos, and cryptocurrency exchanges. Their activities have caused significant global financial losses and demonstrate high technical sophistication.
Goals & Targeting
APT38's primary strategic objective appears to be financial gain, achieved through targetedattacks on financial institutions. They have demonstrated a particular focus on banks and financial services, likely due to the high value of these targets and their vulnerability to financial exploitation. Their targeting has spanned multiple countries, including Bangladesh, Chile, and Mexico, suggesting a global operational reach. The group's ability to adapt its tactics and tools allows it to target a variety of financial sector entities while maintaining a focus on high-value assets. This combination of objectives and targeting strategies makes APT38 a significant threat to the global financial ecosystem.
Enhanced Description
APT38 is a North Korean state-sponsored cyber threat group associated with the Reconnaissance General Bureau. They have been active since at least 2014 and are known for targeting financial institutions, including banks, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs across multiple countries. APT38 has conducted several high-profile attacks, such as the 2016 Bank of Bangladesh heist, where they stole $81 million, and attacks against Bancomext and Banco de Chile. Their operations often involve sophisticated tactics, techniques, and procedures (TTPs), including the use of malware and social engineering. Some of their attacks have been destructive in nature, indicating a capability for both financial gain and impact through data destruction or disruption. APT38 is also linked to activities under the broader Lazarus Group umbrella, which covers multiple North Korean state-sponsored cyber threat groups.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT38 has been involved in numerous campaigns targeting financial institutions globally. Their operations include credential theft, network pivoting, and destructive activities such as data encryption and system shutdowns. Notable campaigns include the FASTCash and Far Eastern International Bank campaigns, where they exploited SWIFT vulnerabilities to siphon funds. APT38's ability to adapt their tactics while maintaining a focus on high-value targets makes them a persistent and evolving threat to the financial sector.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is high confidence in APT38's identity as a North Korean state-sponsored group, though some ambiguity exists due to the overlapping nature of North Korean cyber threat groups. The linkage between Lazarus Group and APT38 adds complexity to precise attribution. Additional gaps include the full scope of their tools and techniques used beyond what is currently documented.
FASTCash
Far Eastern International Bank
No observed data linked yet.
75
Techniques
61
Tools
2
Campaigns
40
IOCs
0
Observed Data
12
Tactics