APT38

MITRE ATT&CK: G0082 View on attack.mitre.org

Aliases: NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM, APT38

First seen
2014-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
74 (4 malicious)
Last IoC activity
2026-09-02 03:20:10
Profile updated
2026-07-07 11:50:35

Targeted industries: financial-services government-and-public-sector

Context

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile; some of their attacks have been destructive. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to APT38 (G0082). The 4 most recently updated:

TypeIndicatorUpdatedSources
hostname firstfromsep.online 2026-09-03 1
hostname cryptorgram.com 2026-08-25 1
hostname chkactive.online 2026-05-06 1
file sample 8d4c3091ce2448c130326c53547a8a45 2025-11-05 1

Detection coverage

  • 10 YARA rules
  • 990 Sigma rules

Malware & tools used

  • Data Encrypted for Impact (attack-pattern)
  • Process Injection (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Modify Registry (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Space after Filename (attack-pattern)
  • Keylogging (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Windows Service (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Visual Basic (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • Malicious Link (attack-pattern)
  • Web Protocols (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Software Packing (attack-pattern)
  • Browser Information Discovery (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Mshta (attack-pattern)

Reports & references

  • Kaspersky — 77908 (report)
  • secureworks.com — Nickel Gladstone (report)
  • MITRE ATT&CK — G0082 (report)
  • CrowdStrike — Report2021Gtr (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • services.google.com — Apt38 Un Usual Suspects (report)
  • CISA — Aa20 239A (report)
  • CrowdStrike — Meet Crowdstrikes Adversary Of The Month For April Stardust Chollima (report)
  • justice.gov — Three North Korean Military Hackers Indicted Wide Ranging Scheme Commit Cyberattacks And (report)

External references