APT38
MITRE ATT&CK: G0082 View on attack.mitre.org
Aliases: NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM, APT38
- First seen
- 2014-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 74 (4 malicious)
- Last IoC activity
- 2026-09-02 03:20:10
- Profile updated
- 2026-07-07 11:50:35
Targeted industries: financial-services government-and-public-sector
Context
APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile; some of their attacks have been destructive. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to APT38 (G0082). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | firstfromsep.online | 2026-09-03 | 1 |
| hostname | cryptorgram.com | 2026-08-25 | 1 |
| hostname | chkactive.online | 2026-05-06 | 1 |
| file sample | 8d4c3091ce2448c130326c53547a8a45 | 2025-11-05 | 1 |
Detection coverage
- 10 YARA rules
- 990 Sigma rules
Malware & tools used
- Data Encrypted for Impact (attack-pattern)
- Process Injection (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Space after Filename (attack-pattern)
- Keylogging (attack-pattern)
- Security Software Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Drive-by Compromise (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Visual Basic (attack-pattern)
- System Shutdown/Reboot (attack-pattern)
- Malicious Link (attack-pattern)
- Web Protocols (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Software Packing (attack-pattern)
- Browser Information Discovery (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Mshta (attack-pattern)
Reports & references
- Kaspersky — 77908 (report)
- secureworks.com — Nickel Gladstone (report)
- MITRE ATT&CK — G0082 (report)
- CrowdStrike — Report2021Gtr (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- services.google.com — Apt38 Un Usual Suspects (report)
- CISA — Aa20 239A (report)
- CrowdStrike — Meet Crowdstrikes Adversary Of The Month For April Stardust Chollima (report)
- justice.gov — Three North Korean Military Hackers Indicted Wide Ranging Scheme Commit Cyberattacks And (report)
External references
- mitre-attack — G0082
- BeagleBoyz
- Stardust Chollima
- APT38
- Bluenoroff
- Sapphire Sleet
- COPERNICIUM
- NICKEL GLADSTONE
- CrowdStrike GTR 2021 June 2021
- DOJ North Korea Indictment Feb 2021
- CISA AA20-239A BeagleBoyz August 2020
- FireEye APT38 Oct 2018
- Kaspersky Lazarus Under The Hood Blog 2017
- CrowdStrike Stardust Chollima Profile April 2018
- Microsoft Threat Actor Naming July 2023
- SecureWorks NICKEL GLADSTONE profile Sept 2021
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy