Microsoft's Threat Intelligence Center tracked PLUTONIUM, subsequently renamed Onyx Sleet under Microsoft's revised naming taxonomy, as a North Korean state-linked threat actor active since at least 2014, associated with clusters also known as DarkSeoul and Andariel, and primarily targeting the energy and defense industries in India, South Korea, and the United States. In a July 2022 report on the H0lyGh0st ransomware operator DEV-0530, Microsoft assessed likely overlap between the two groups: DEV-0530 email accounts were observed communicating with PLUTONIUM attacker accounts, the two operated from shared infrastructure and used custom malware controllers with similar naming conventions, and DEV-0530 was seen using tools created exclusively by PLUTONIUM. Despite these connections, differences in operational tempo, targeting, and tradecraft led Microsoft to assess DEV-0530 and PLUTONIUM as distinct groups, raising the possibility that individuals tied to PLUTONIUM infrastructure were moonlighting on ransomware for personal financial gain rather than acting under state direction.
Actors
249 actors
PolinRider is the name OpenSourceMalware gave to a 2026 supply-chain campaign it attributes to a North Korean, Lazarus Group-linked threat actor that implants malicious JavaScript into open-source projects on GitHub and npm. Researchers describe it as a parallel or sub-campaign of the broader Contagious Interview activity, noting it initially made use of credentials stolen through a related campaign called TasksJacker. The threat actor forks popular repositories or compromises developers' own repositories, then appends obfuscated JavaScript to frequently executed but rarely reviewed build and configuration files, such as PostCSS, Tailwind CSS, and ESLint configuration files, as well as hiding payloads inside font files. Malicious npm packages were also published to distribute the same payload. The campaign primarily compromises individual, often job-seeking, software developers rather than organizations, and researchers observed its confirmed footprint of poisoned repositories grow substantially between March and July 2026, with targeting spanning ecosystems including Visual Studio Code, Apache Superset, Rails, LangFlow, and Expo.
Pompilus is Symantec’s tracking name for the subset of North Korean Lazarus activity that conducts Operation Dream Job. Symantec applied the name while reporting in April 2022 on an espionage campaign against South Korean chemical and information-technology organizations, describing it as a continuation of activity first observed in August 2020. The operation uses fabricated job offers to persuade targets to open malicious links or attachments, with earlier campaigns reaching defense, government, and engineering personnel. In the 2022 intrusion set, attackers delivered malicious web files, injected trojanized libraries into legitimate software, deployed shellcode loaders and additional malware, moved laterally through Windows management tools, dumped credentials, created scheduled tasks for persistence, and used screenshot, proxy, file-copy, and transfer utilities. Symantec assessed that the campaign sought intellectual property useful to North Korea’s strategic chemical, engineering, and defense interests.
CrowdStrike Intelligence, in a January 2026 report, reassessed its long-standing LABYRINTH CHOLLIMA attribution and determined that three specialized North Korean adversaries emerged from a shared malware-framework lineage between 2018 and 2020: the core, espionage-focused LABYRINTH CHOLLIMA, GOLDEN CHOLLIMA, and PRESSURE CHOLLIMA. PRESSURE CHOLLIMA likely diverged around February 2019 with an early experimental downloader later replaced by a more advanced downloader publicly tracked elsewhere under a different name. Unlike GOLDEN CHOLLIMA's steadier, lower-value thefts, PRESSURE CHOLLIMA pursues high-payout cryptocurrency targets worldwide regardless of geography and is responsible for the DPRK's highest-profile cryptocurrency heists, including the two largest thefts on record and several other multi-million-dollar incidents linked through reused wallets. It deploys sophisticated, low-prevalence custom implants delivered via malicious Node.js and Python projects. Later 2026 CrowdStrike global and financial-sector threat reporting attributed to PRESSURE CHOLLIMA the largest single cryptocurrency theft ever reported, $1.46 billion stolen in 2025 through trojanized software distributed via a supply-chain compromise. Despite operating as a distinct unit, PRESSURE CHOLLIMA shares tooling and infrastructure with its sibling groups, reflecting centralized coordination within the DPRK cyber apparatus.
Pungsan is a cluster that Datadog's Security Research team named 'Stressed Pungsan' after discovering it in July 2024, assessing that its tactics, infrastructure, and targeting align closely with what Microsoft tracks as Moonstone Sleet, a DPRK-aligned actor. Datadog identified the cluster through its open-source package-scanning tooling, which flagged two malicious npm packages published to the npm registry on the same day in July 2024 by a since-removed publishing account. The packages copied code from a popular, legitimate open-source configuration library and added a preinstall script that downloaded a file disguised as a data file, renamed it into a Windows dynamic-link library, and loaded it into memory using a trusted system binary, a technique used to evade detection while gaining a foothold in developer and Windows environments. Consistent with broader Pyongyang-aligned software-supply-chain activity, this actor's post-compromise objective is to steal personal information and API or cloud-access keys and to move laterally into connected environments.
Recorded Future's Insikt Group first reported on PurpleBravo in February 2025, tracking it as a North Korean-linked cluster formerly designated Threat Activity Group 120 that overlaps with the Contagious Interview campaign, first documented in November 2023 and also known in open sources as CL-STA-0240, Famous Chollima, and Tenacious Pungsan. The group primarily targets software developers, particularly in the cryptocurrency and IT services sectors, using fake recruiter personas, fictitious front companies, and fraudulent job interviews and coding tests to deliver malware, including the BeaverTail infostealer, the InvisibleFerret backdoor, and OtterCookie, aimed at stealing browser credentials and cryptocurrency wallet data. Insikt Group has identified dozens of BeaverTail and GolangGhost command-and-control servers and thousands of IP addresses linked to likely victims across cryptocurrency, IT services, financial services, and software development industries, and distinguishes PurpleBravo from, while noting some overlap with, PurpleDelta, its separate designation for North Korean fraudulent IT worker operations.
Recorded Future's Insikt Group uses PurpleDelta as its designation for clusters of North Korean IT workers operating a fraudulent employment scheme, comprising multiple operators likely based in China with a documented nexus to Shenyang. One cluster applied to more than 1,100 companies, mostly in software and technology, staffing and consulting, and healthcare and biotechnology, between late 2024 and early 2025. Operators maintained at least 22 fabricated personas supported by AI-generated photographs, custom ChatGPT assistants, illicitly obtained identity documents, anti-detect browsers, and temporary phone services, submitting dozens of applications daily and using live transcription and AI-generated answers to pass technical interviews; Recorded Future assesses operators were highly likely to have secured employment at ten or more organizations, creating insider risk through recorded meetings and continued personal-device access. Recorded Future notes overlap between PurpleDelta and the North Korean clusters Jasper Sleet, UNC5267, Wagemole, and Famous Chollima, as well as a related cluster, PurpleBravo, that delivers malware through fraudulent recruitment targeting cryptocurrency-sector developers, with proceeds ultimately supporting North Korea's sanctioned military and nuclear programs.
Elastic Security Labs disclosed in a November 2023 report an intrusion set it tracks as REF7001, which targeted blockchain engineers at a cryptocurrency exchange platform; Elastic attributed the activity to North Korea and noted overlaps with the Lazarus Group based on techniques, network infrastructure, and code-signing certificates. The attackers impersonated members of the blockchain engineering community on a public Discord server and social-engineered a victim into downloading an archive disguised as a cryptocurrency arbitrage bot. Running the bundled script triggered a multi-stage macOS infection chain involving remotely hosted droppers, an obfuscated loader, and a persistence component that hijacked the legitimate Discord application's launch process, ultimately executing a final-stage payload capable of information gathering, data exfiltration, and arbitrary command execution. The intrusion relied on defense-evasion techniques, including reflective in-memory loading of binaries and a macOS code-signing technique previously linked to the Lazarus Group's 3CX supply-chain compromise.
REF9134 is Elastic Security Labs’ name for a macOS intrusion discovered in late May 2023 at a prominent Japanese cryptocurrency exchange. Elastic introduced the designation in June 2023 while investigating activity later associated with the JOKERSPY toolset. The adversary already had access when researchers observed execution of a self-signed Swift binary known as xcc, attempts to replace the macOS Transparency, Consent, and Control database, and deployment of a Python backdoor named sh.py. The backdoor collected host information, executed shell commands and Python code, managed files, and transferred data, while also installing the open-source Swiftbelt enumeration utility. Elastic assessed that initial access most likely involved a malicious or backdoored plugin or third-party dependency. The activity combined trust-control bypass, system discovery, persistent command execution, and targeted collection against a cryptocurrency-sector victim.
Elastic Security Labs used the campaign designator REF9135 for a DPRK-linked intrusion set responsible for a sustained compromise at a cryptocurrency payment services provider, identified through host, binary, and network analysis that tied the activity with high confidence to the Lazarus Group, the DPRK's cybercrime and espionage organization, and specifically to its financially motivated BlueNorOff sub-unit, previously linked to the 2016 Bangladesh Bank SWIFT theft. REF9135 delivered an actively developed variant of the macOS RUSTBUCKET malware via a multi-stage AppleScript, Swift, and Rust loader chain that added a LaunchAgent-based persistence mechanism and evaded VirusTotal signature detection at the time of discovery. Operators rapidly rotated dynamic command-and-control domains and IP infrastructure, some of which shared TLS certificate fingerprints and hosting with infrastructure documented under the DangerousPassword phishing campaign and APT38, to sustain long-term access while frustrating researcher collection efforts.
REF9403 is the tracking designation Elastic Security Labs assigned to a DPRK-aligned campaign, identified in 2026, that is linked to the broader Contagious Interview activity. Elastic discovered the operation after an operator posted a fake developer job offer in Elastic's own community Slack workspace and directed an interested user to complete a coding assignment using a trojanized software repository. The malicious repositories concealed JavaScript payloads as Base64 fragments hidden inside SVG image files, which were reassembled and executed to deploy credential, cryptocurrency-wallet, clipboard, and file-stealing modules alongside a remote-access capability. Elastic linked the activity to Contagious Interview based on code, behavioral, and infrastructure overlaps with malware known as OTTERCOOKIE, noting that the historical distinction between OTTERCOOKIE and an earlier malware family, BEAVERTAIL, has become increasingly blurred as the operators converge capabilities into single payloads targeting software developers.
RGB-D3 is a North Korea-linked cluster described by IssueMakersLab as primarily targeting aerospace and defense companies. One observed lure used a job description associated with General Dynamics Mission Systems, a U.S. defense and aerospace business, to distribute malware.
South Korean research collective IssueMakersLab tracked RGB-D5, a North Korean state threat actor under the Reconnaissance General Bureau that its reporting treats as equivalent to, or inclusive of, the actor commonly called Kimsuky, through a series of short posts issued between April and December 2020. The earliest post described a 'Daily Coffee' operation in which the actor launched spearphishing attacks against dozens to hundreds of South Korean key figures on a near-daily basis. A following post detailed RGB-D5's distribution of Android malware built from an open-source Android remote access tool to South Korean targets. IssueMakersLab also distinguished RGB-D5 from a related cluster it labeled RGB-D3 by target set within the defense-contractor sector: RGB-D3 focused on aerospace and defense firms, while RGB-D5 primarily targeted companies producing artillery ammunition and military vehicles. Later in 2020, RGB-D5 was linked to attacks on COVID-19 vaccine pharmaceutical developers and the World Health Organization across the United States, South Korea, Germany, Sweden, and the United Kingdom, and to a spearphishing campaign against more than 40 South Korean companies, universities, financial institutions, law firms, and media organizations.