APT38 is a North Korean state-backed cyber threat actor widely associated with financially motivated operations and commonly treated as a subgroup or operational cluster within the broader Lazarus ecosystem. It is closely linked with the aliases BlueNoroff, Sapphire Sleet, Stardust Chollima, CageyChameleon, Copernicium, DangerousPassword, Leery Turtle, Nickel Gladstone, TA444, and UNC1069. The actor is best known for targeting financial institutions, cryptocurrency organizations, and payment infrastructure, including operations involving SWIFT-related systems and theft-oriented intrusions. APT38 has conducted sophisticated multi-stage intrusions that combine social engineering, malware delivery, persistence, host reconnaissance, data collection, and remote command execution. Reported tradecraft includes spearphishing and lures that attempt to induce victims to enable malicious macros or execute attacker-controlled content, as well as more recent cryptocurrency-focused social-engineering campaigns. The actor has used PowerShell, VBScript, malicious HTML execution via renamed mshta, Windows API-based execution, and backdoors that communicate over HTTP and HTTPS. Associated malware and tooling include NESTEGG for file transfer, QUICKRIDE for backdoor communications, CLEANTOAD for Registry modification, CLOSESHAVE for artifact deletion, DYEPACK for manipulation of SWIFT-related database records, and KEYLIME for keylogging. Post-compromise behavior attributed to APT38 includes detailed host and user discovery, process and service reconnaissance, network share enumeration, collection of data from compromised hosts, and secure deletion of artifacts to hinder investigation. The actor has used Task Scheduler for persistence and has modified the Windows Registry. It has also been observed leveraging Sysmon for environmental awareness and using tunneling utilities to obtain shell access. In addition to traditional financial-sector intrusions, reporting links this cluster to cryptocurrency-sector targeting and malware families associated with the broader Lazarus/BlueNoroff ecosystem, including WAVESHAPER-related activity and TraderTraitor-linked operations. APT38's dominant profile is a DPRK-backed financial theft actor: technically mature, operationally patient, and focused on monetization through compromise of banks, payment systems, and digital-asset organizations rather than conventional ransomware or destructive campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
62 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
68 malware families attributed to this actor across reporting.
63 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Kaspersky Lab confirms that sap.misapor[.]ch was compromised as well, and was spreading exploits for Adobe Flash Player and Microsoft Silverlight. Some of the known vulnerability CVEs observed in attacks originate from that website: 2. CVE-2015-8651
Some of the known vulnerability CVEs observed in attacks originate from that website: 4. CVE-2016-0034
Kaspersky Lab confirms that sap.misapor[.]ch was compromised as well, and was spreading exploits for Adobe Flash Player and Microsoft Silverlight. Some of the known vulnerability CVEs observed in attacks originate from that website: 3. CVE-2016-1019
Some of the known vulnerability CVEs observed in attacks originate from that website: 1. CVE-2016-4117
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
2 more CVEs tied to this actor tracked in Mallory.
1,017 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparison point for a similar fake recruiter / social-engineering delivery flow, but not identified as the confirmed operator of this specific campaign.
Referenced as using fake Zoom and Teams ClickFix lures in related social-engineering campaigns.
Referenced as a wallet-targeting threat actor associated with ClickFix-style activity, used here as comparative context for credential and session cleanup after remote-access exposure.
Active software supply chain attacker targeting developer ecosystems such as package registries, CI/CD pipelines, container registries, and IDE extensions to gain access to production systems, cloud environments, and customer networks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.