APT45
- First seen
- 2009-01-01 00:00:00
- Origin
- KP
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:16:49
Targeted industries: defense-and-aerospace financial-services government-and-public-sector healthcare-and-pharmaceutical energy-and-utilities
Context
APT45 is a North Korean cyber threat actor that has been active since at least 2009. They have conducted espionage campaigns targeting government agencies and defense industries, as well as financially-motivated operations, including ransomware development. APT45 has targeted critical infrastructure, financial organizations, nuclear research facilities, and healthcare and pharmaceutical companies. They use a mix of publicly available tools, modified malware, and custom malware families in their operations.
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- cloud.google.com — Apt45 North Korea Digital Military Machine (report)
Attributed from
- Andariel Espionage Activity (campaign)