APT-C-26 is a designation used by Qihoo 360 for an activity cluster suspected of being operated by the Lazarus Group and directed against cryptocurrency institutions and individuals. In 2018, 360's Advanced Threat Response Team uncovered an attack in which the group distributed a trojanized cryptocurrency trading application built on an open-source trading tool, available for both Windows and macOS. The tampered software concealed a backdoor component that activated as soon as the program launched, collecting the victim's process list, computer name, and system information, encrypting it, and sending it to a command-and-control server, which could then return additional malicious code for execution. Continued monitoring by 360 found the same operators still active in 2019, having registered new lookalike domains and built a further trojanized automated-trading tool sharing the same code structure and attack framework as the earlier campaign. This later tool was promoted to staff at digital-currency exchanges as a phishing lure, leading to further compromises and theft of cryptocurrency assets, reflecting a sustained, financially motivated campaign against the cryptocurrency sector.
Actors
246 actors
APT-C-28 is Qihoo 360's designation for a Northeast Asian espionage group that the company was publicly tracking under that label by April 2023. Its activity is described as reaching back to at least 2012 and remaining active through 2025, with a strong focus on South Korea and other Asian countries. Reported targets include government personnel and organizations in the chemical, electronics, manufacturing, aerospace, automotive, and healthcare sectors, while the principal objective is theft of strategic military, political, economic, and other sensitive information. Operations use tailored phishing themes and malicious documents or shortcut files to launch scripts, evade privilege controls, establish persistence, and deploy remote-access malware. Later campaigns increasingly centered on RokRat: encrypted payloads were first fetched from cloud services, then embedded directly in shortcut files and decrypted in memory, reflecting adaptation to faster blocking of malicious cloud links while preserving long-term surveillance and data theft.
APT-C-55 is the designation Chinese security firm Qihoo 360 uses for the Kimsuky threat group (also tracked under aliases including Mystery Baby, Baby Coin, Smoke Screen, and Black Banshee), a suspected East Asian state-linked espionage actor. Qihoo 360's threat research team has tracked the group since at least November 2021, when it caught a sample abusing a modified commercial browser password-recovery tool to test credential-collection functionality, injected into svchost.exe after RC4/ZLIB-decrypted staging. The group primarily targets South Korean government, defense-industrial, media, and academic/education organizations, relying on spear-phishing with topical lure documents, including HWP/Hancom-themed loaders, to build trust before harvesting sensitive information. Qihoo 360 has also documented the group's use of the BabyShark malware component, first seen in February 2019 targeting United States national-security think tanks and academic institutions, later repurposed for espionage on nuclear-security and Korean-peninsula issues as well as financially motivated cryptocurrency-related intrusions; BabyShark uses OneDrive-hosted staging URLs and VBScript decryption chains. Qihoo 360 notes infrastructure overlap with the Konni activity cluster.
APT-Q-1 is Qianxin's internal tracking designation for Lazarus, a threat group described as active since at least 2009. Qianxin characterizes the group as conducting espionage and financially motivated operations, initially emphasizing government targets and later expanding toward financial institutions, cryptocurrency businesses, and supply chains. Its tradecraft includes spearphishing, watering-hole attacks, destructive or ransomware payloads, exploitation for lateral movement, and remote-access tooling. In a 2024 recruitment-themed campaign assessed as possibly related to the group, operators used fabricated employer and developer identities on professional platforms to entice blockchain developers into running malicious project code. The code stole browser credentials and cryptocurrency-wallet data across Windows, Linux, and macOS and installed additional payloads. Qianxin treated the campaign attribution cautiously, based on infrastructure overlap and similarities in targeting and social engineering.
APT-Q-2 is QiAnXin's internal tracking designation for Kimsuky, an espionage actor publicly disclosed in 2013 with activity traced to 2012. QiAnXin describes a primary focus on South Korea, especially defense, education, energy, government, healthcare, and think-tank targets, with confidential-information theft as the main objective. Its access methods include social engineering, spear-phishing, watering holes, and malicious tooling for Windows and Android. A 2024 campaign disguised data-stealing programs as legitimate South Korean software installers; the payload collected system, user, browser, file-transfer, secure-shell, document, and screenshot data, exfiltrated encrypted archives, and deleted itself to reduce traces. Later 2024 activity expanded toward European defense-sector personnel through fake recruitment documents. Those samples used script and executable droppers, encrypted configuration and command traffic, persistence through services or registry startup, file download, command execution, and rapid code changes, although QiAnXin kept that specific European attribution qualified.
Qianxin's Red Drip Team assigned the internal tracking designator APT-Q-3 to the group it tracks as Group123, an espionage-motivated threat actor believed active since 2012 and linked to earlier reported operations known as Operation Daybreak and Operation Erebus. The group initially focused on South Korean targets before expanding after 2017 to Japan, Vietnam, and the Middle East, striking chemical, electronics, manufacturing, aerospace, automotive, and healthcare organizations, and later also government, defense-policy, and diplomatic targets. It relies on tailored spear-phishing lures, including compressed archives containing disguised shortcut (LNK) files, Hangul Word Processor documents, and PDF or audio decoys referencing Korean political and defense events, that drop malicious RTF and PowerShell chains ultimately deploying the RokRAT backdoor, which abuses cloud storage services such as OneDrive, Dropbox, Box, and Yandex for command-and-control and can capture screenshots, log keystrokes, and evade virtual machines. Analysts have separately noted feature overlap between this group and the Kimsuky cluster.
FireEye (later Mandiant) introduced the name APT37 (Reaper) in a 2018 special report examining a suspected North Korean cyber-espionage group first observed via a February 2018 Adobe Flash zero-day blog post, assessing that APT37 aligns with activity separately reported as Scarcruft and Group123. FireEye assessed with high confidence that APT37 operates on behalf of the North Korean government, active since at least 2012 and focused primarily on covert intelligence gathering supporting North Korea's military, political, and economic interests. From 2014 to 2017 the group concentrated on South Korean government, military, defense-industrial, and media targets before expanding in 2017 to Japan, Vietnam, the Middle East, and additional sectors including chemicals, electronics, manufacturing, aerospace, automotive, and healthcare, alongside continued targeting of North Korean defectors and human-rights organizations. APT37 relies on spear phishing with Hangul Word Processor exploits and strategic web compromises, rapid adoption of zero-day vulnerabilities, cloud-hosted and compromised-site command and control, and a malware suite including the DOGCALL backdoor and the RUHAPPY wiper capable of overwriting a system's master boot record.
APT38 is the name FireEye introduced in 2018 for a distinct, financially motivated North Korean state-sponsored activity cluster separated from its broader espionage tracking. FireEye traced operations to February 2014 and described compromises of more than sixteen organizations across at least thirteen countries, with banks and other financial institutions as the central targets. The group's objective is to manipulate interbank systems and raise large sums for the North Korean regime. Early work emphasized learning financial environments in Southeast Asia; later operations expanded globally and became more complex, specialized, and destructive. APT38 conducts extensive personnel and vendor research, uses watering holes or vulnerable servers for access, maps networks, maintains long dwell times, and closely studies transaction systems. It deploys custom backdoors and monitoring tools, pivots to SWIFT servers, alters transaction records to conceal fraudulent transfers, and may finish by securely deleting artifacts, clearing logs, deploying wipers, or using ransomware as misdirection and evidence destruction.
APT43 is a North Korean state-sponsored cyber operator publicly identified by Mandiant in March 2023, assessed to have been active since at least 2018 in support of the Reconnaissance General Bureau (RGB), North Korea's main foreign intelligence service. Mandiant and other researchers noted that activity later consolidated under the APT43 name had previously been publicly reported under other identifiers, including Kimsuky and Thallium. The group's primary mission is strategic intelligence collection aligned with Pyongyang's geopolitical and nuclear priorities, achieved mainly through tailored spear-phishing, credential harvesting via spoofed websites, and elaborate fraudulent personas (including posing as journalists and think-tank analysts) to build rapport with targets. Its focus is regionally centered on South Korea and the United States, with additional targeting of Japan and Europe, spanning government, defense, academic, non-profit, media, and manufacturing sectors tied to foreign policy and nuclear/nonproliferation issues. To fund its espionage operations, APT43 steals and launders cryptocurrency through hash-rental and cloud-mining services, and it has coordinated with other North Korean cyber operators on shared campaigns and tasking.
Mandiant assesses with high confidence that APT45 is a moderately sophisticated North Korean state-sponsored cyber operator active since at least 2009, and with moderate confidence that it operates in support of North Korea's Reconnaissance General Bureau. Its earliest observed activity consisted of espionage against government agencies and the defense industry from around 2017, followed by targeting of nuclear-related entities including a 2019 intrusion at a nuclear power plant in India, intellectual property theft from a multinational crop-science division in 2020, and sustained targeting of the healthcare and pharmaceutical sectors during and after the COVID-19 pandemic. APT45 has also targeted the financial sector, including a 2016 intrusion against a South Korean financial organization and 2021 spear-phishing of a South Asian bank, and Mandiant assesses with moderate confidence that it has developed and possibly deployed ransomware to generate revenue. Activity attributed to APT45 has also been publicly reported under the names Andariel, Onyx Sleet, Stonefly, and Silent Chollima, and is frequently linked to the broader Lazarus Group.
Google's Threat Analysis Group publicly described ARCHIPELAGO in April 2023 as its name for a subset of APT43 activity, which it had tracked since 2012. The North Korea-linked cluster targets people working on sanctions, human rights, non-proliferation, and other North Korea policy issues, including government and military personnel, think tanks, policymakers, academics, and researchers in South Korea, the United States, and elsewhere. Its operations evolved from conventional credential phishing toward rapport-building impersonation, browser-in-the-browser login pages, individualized documents hosted on cloud services, and greater malware use. ARCHIPELAGO has delivered password-protected files and layered ISO archives, encoded payloads and command instructions in cloud-hosted filenames, and used malicious browser extensions to steal credentials, cookies, and webmail contents.
ATK117 is profiled by Thales and Verint in the Cyberthreat Handbook as a North Korean state-sponsored cyberthreat actor with prerogatives similar to Unit 180 of the North Korean army's General Reconnaissance Bureau, tracked under the aliases APT38 and Bluenoroff and described as a financially motivated entity within the broader Lazarus umbrella. Active since at least 2014, the group develops SWIFT-focused banking malware and cryptocurrency-theft tooling, and is linked to a series of attempted and successful bank heists, including a 2014 Southeast Asian bank intrusion, the 2015 attempted heist at TPBank, the 2016 Bangladesh Bank SWIFT theft, an October 2016 watering-hole campaign, the 2017 Far Eastern International Bank heist, and 2018 intrusions at Bancomext, three Mexican banks, and Banco de Chile, along with a 2019 campaign targeting Korean Bitcoin traders. The group has used destructive disk-wiping malware as a distraction technique, employs defense-evasion methods including false-flag artifacts and living-off-the-land tools, and maintains a broad, purpose-built malware and tooling arsenal.
ATK3 is the designation used by Thales, in its Cyberthreat Handbook produced with Verint, for a North Korean state-sponsored threat actor also referenced under aliases including COVELLITE, Hidden Cobra, Lazarus, and Lazarus Group. Thales ties the activity to Bureau 121 of North Korea's Reconnaissance General Bureau and notes that the "Lazarus" umbrella is often used to describe several functionally distinct North Korean cyber units, including financially focused subgroups elsewhere tracked as APT38, Stardust Chollima, or BlueNoroff. According to the Handbook, the actor's operations combine cyber espionage, destructive attacks, and financially motivated theft, targeting government, defense, financial services, energy, media, healthcare, and manufacturing organizations worldwide. Cited activity includes the 2014 Sony Pictures intrusion, the 2016 Bangladesh Bank SWIFT heist, the 2017 WannaCry outbreak, an intrusion at India's Kudankulam Nuclear Power Plant, and the Dream Job campaign that used fraudulent job offers to lure victims into installing malware.
Thales documented ATK4 in its 2022 Cyber Threat Handbook as a North Korean state-sponsored espionage group active since at least 2012 and linked the label to APT37. Its primary mission is collecting intelligence that supports North Korea's military, political, and economic interests. From 2014 through 2017, the group concentrated on South Korean government, defense, industry, and media targets before expanding to organizations in the Middle East, Japan, Vietnam, Russia, and the United States where North Korean interests were involved. ATK4 uses spearphishing, strategic website compromises, torrent-based delivery, Korean-language decoy documents, compromised servers, messaging platforms, cloud services, and social networks. It rapidly incorporates newly disclosed and zero-day vulnerabilities and has deployed malicious documents and multiple malware families against governments, journalists, human-rights interests, and other public- and private-sector targets.
Palo Alto Networks Unit 42 tracks Alluring Pisces as one of at least six North Korean threat groups operating under the Reconnaissance General Bureau, also known in industry reporting as APT38, Bluenoroff, and Sapphire Sleet. The group has targeted financial institutions, cryptocurrency businesses, and automated teller machines, and has carried out significant cyber heists for financial gain. Its malware arsenal spans Windows, macOS, and Linux and includes the macOS backdoor RustBucket, delivered through a multi-stage AppleScript, Swift, and Objective-C infection chain that masquerades as a PDF viewer; KANDYKORN, a five-stage macOS payload delivered through social-engineering lures that provides information gathering, data exfiltration, and arbitrary command execution; and ObjCShellz, a lightweight Objective-C remote-shell backdoor deployed as a second-stage payload within the RustBucket campaign. The group's activity reflects a sustained focus on generating illicit revenue through cryptocurrency theft and financial-sector intrusions in support of North Korean state objectives.