BlueHornet

Aliases: APT49, AgainstTheWest

Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Profile updated
2026-07-07 12:08:37

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:kp country_code:ir country_code:ru

Context

BlueHornet is an advanced persistent threat group targeting government organizations in China, North Korea, Iran, and Russia. They have compromised and leaked data from other APT groups like Kryptonite Panda and Lazarus Group. BlueHornet has been involved in campaigns such as Operation Renminbi, Operation Ruble, and Operation EUSec, focusing on exfiltrating region-specific data and selling it on the dark web. They have also been known to collaborate with different threat actors and have recently disclosed a zero-day exploit in NGINX 1.18.

Reports & references

  • Mandiant — Killnet New Capabilities Older Tactics (report)
  • cyberint.com — Bluehornet One Apt To Terrorize Them All (report)
  • csoonline.com — Cyberattacks Against Governments Jumped 95 In Last Half Of 2022 Cloudsek Says (report)

External references