Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM, APT38, ElectricFish, the Lazarus Group, TraderTraitor, Stardust Cholima, TA444, tracked as, Hidden Cobra, GhostCall, GhostHire, targeting executives, the North Korea, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, BlueNoroff

Description

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.(Citation: CISA AA20-239A BeagleBoyz August 2020) Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext (Citation: FireEye APT38 Oct 2018) and Banco de Chile (Citation: FireEye APT38 Oct 2018); some of their attacks have been destructive.(Citation: CISA AA20-239A BeagleBoyz August 2020)(Citation: FireEye APT38 Oct 2018)(Citation: DOJ North Korea Indictment Feb 2021)(Citation: Kaspersky Lazarus Under The Hood Blog 2017) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Goals & Targeting

Targeted Sectors

Financial services
Financial services
Government
Defense
Telecommunications
Healthcare
Education
Manufacturing
Non profit
Media
Energy
Critical infrastructure
Pharmaceutical
Aviation
Hospitality
Aerospace
Retail
Entertainment
Gaming
Information technology
Think tank
Transportation
Mining
Chemical
Legal services
Nuclear
Oil gas
Maritime
Construction
Utilities

Targeted Countries / Regions

US
CN
KP
RU
IR
TW
VN
JP
IL
KR
GB
AU
SA
PK
AE
UA
IN
SG
DE
BY
TR
MX
ES
PL
CA
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

· 1 week ago

Executive Summary

APT38, also known as NICKEL GLADSTONE, BeagleBoyz, and Bluenoroff, is a North Korean state-sponsored cyber threat group primarily targeting financial institutions for financial gain. They are known for sophisticated attacks including bank heists, SWIFT system exploitation, and destructive operations against banks, casinos, and cryptocurrency exchanges. Their activities have caused significant global financial losses and demonstrate high technical sophistication.

Goals & Targeting

APT38's primary strategic objective appears to be financial gain, achieved through targetedattacks on financial institutions. They have demonstrated a particular focus on banks and financial services, likely due to the high value of these targets and their vulnerability to financial exploitation. Their targeting has spanned multiple countries, including Bangladesh, Chile, and Mexico, suggesting a global operational reach. The group's ability to adapt its tactics and tools allows it to target a variety of financial sector entities while maintaining a focus on high-value assets. This combination of objectives and targeting strategies makes APT38 a significant threat to the global financial ecosystem.

Enhanced Description

APT38 is a North Korean state-sponsored cyber threat group associated with the Reconnaissance General Bureau. They have been active since at least 2014 and are known for targeting financial institutions, including banks, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs across multiple countries. APT38 has conducted several high-profile attacks, such as the 2016 Bank of Bangladesh heist, where they stole $81 million, and attacks against Bancomext and Banco de Chile. Their operations often involve sophisticated tactics, techniques, and procedures (TTPs), including the use of malware and social engineering. Some of their attacks have been destructive in nature, indicating a capability for both financial gain and impact through data destruction or disruption. APT38 is also linked to activities under the broader Lazarus Group umbrella, which covers multiple North Korean state-sponsored cyber threat groups.

Key Capabilities

  • Sophisticated cyberattacks targeting financial institutions
  • Financial heists through SWIFT system exploitation
  • Destructive operations including ransomware and data destruction
  • Use of malware, social engineering, and persistence techniques

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1053.005
T1204.002
T1529
T1218.007
T1583.001
T1070.006
T1480.002
T1112
T1588.002
T1218.001
T1036.003
T1486
T1518.001
T1565.003
T1569.002

Software / Tooling

HOPLIGHT
DarkComet
KillDisk
ECCENTRICBANDWAGON

Campaigns & Victims

APT38 has been involved in numerous campaigns targeting financial institutions globally. Their operations include credential theft, network pivoting, and destructive activities such as data encryption and system shutdowns. Notable campaigns include the FASTCash and Far Eastern International Bank campaigns, where they exploited SWIFT vulnerabilities to siphon funds. APT38's ability to adapt their tactics while maintaining a focus on high-value targets makes them a persistent and evolving threat to the financial sector.

IOC Patterns

  • Spear-phishing emails with malicious attachments or links
  • Use of custom malware binaries for credential theft
  • Network traffic indicative of C2 communication channels
  • Scheduled tasks and process injection activities
  • Destruction or encryption of sensitive data

Recommended Actions

  • Implement multi-factor authentication (MFA) for SWIFT systems
  • Deploy advanced endpoint detection and response tools to monitor for APT38's TTPs
  • Conduct regular phishing simulations to improve employee awareness
  • Monitor network traffic for IOC patterns associated with APT38
  • Perform regular security audits of financial systems and networks

Suggested Tags

APT
financial-gain
cyberespionage
banking
malware
SWIFT
NorthKorea

Confidence Assessment

There is high confidence in APT38's identity as a North Korean state-sponsored group, though some ambiguity exists due to the overlapping nature of North Korean cyber threat groups. The linkage between Lazarus Group and APT38 adds complexity to precise attribution. Additional gaps include the full scope of their tools and techniques used beyond what is currently documented.

ATT&CK Techniques

Defense impairment
8 techniques
Discovery
9 techniques
Execution
11 techniques
Impact
9 techniques
Stealth
17 techniques

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. CrowdStrike GTR 2021 June 2021 — CrowdStrike. (2021, June 7). CrowdStrike 2021 Global Threat Report. Retrieved September 29, 2021.
  2. DOJ North Korea Indictment Feb 2021 — Department of Justice. (2021, February 17). Three North Korean Military Hackers Indicted in Wide-Ranging Scheme to Commit Cyberattacks and Financial Crimes Across the Globe. Retrieved June 9, 2021.
  3. CISA AA20-239A BeagleBoyz August 2020 — DHS/CISA. (2020, August 26). FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks. Retrieved September 29, 2021.
  4. FireEye APT38 Oct 2018 — FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.
  5. Kaspersky Lazarus Under The Hood Blog 2017 — GReAT. (2017, April 3). Lazarus Under the Hood. Retrieved April 17, 2019.
  6. CrowdStrike Stardust Chollima Profile April 2018 — Meyers, Adam. (2018, April 6). Meet CrowdStrike’s Adversary of the Month for April: STARDUST CHOLLIMA. Retrieved September 29, 2021.
  7. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  8. SecureWorks NICKEL GLADSTONE profile Sept 2021 — SecureWorks. (2021, September 29). NICKEL GLADSTONE Threat Profile. Retrieved September 29, 2021.
  9. attack.mitre.org — Cited by web research for: Sandworm Team
  10. attack.mitre.org — Cited by web research for: T1548
  11. www.microsoft.com — Cited by web research for: Payload
  12. apt.etda.or.th — Cited by web research for: RustBucket
  13. www.huntress.com — Cited by web research for: SpectralBlur

Intel Summary

75

Techniques

61

Tools

2

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

APT
financial-gain
cyberespionage
banking
malware
SWIFT
NorthKorea

Details

MITRE ID
G0082
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
North Korea (KP)
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--00f67a77-86a4-4adf-be26-1a54fc713340
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.