APT45

First seen
2009-01-01 00:00:00
Origin
KP
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:16:49

Targeted industries: defense-and-aerospace financial-services government-and-public-sector healthcare-and-pharmaceutical energy-and-utilities

Context

APT45 is a North Korean cyber threat actor that has been active since at least 2009. They have conducted espionage campaigns targeting government agencies and defense industries, as well as financially-motivated operations, including ransomware development. APT45 has targeted critical infrastructure, financial organizations, nuclear research facilities, and healthcare and pharmaceutical companies. They use a mix of publicly available tools, modified malware, and custom malware families in their operations.

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • cloud.google.com — Apt45 North Korea Digital Military Machine (report)

Attributed from

  • Andariel Espionage Activity (campaign)

External references