Actors

249 actors

RedEyes is a name AhnLab's security response center uses for a North Korean-linked hacking group it began documenting in March 2018, based on a sixteen-month study of malicious Hangul Word Processor documents collected between September 2016 and December 2017, in which the group, internally labeled Group A, was found responsible for roughly a quarter of the malicious samples. AhnLab treats RedEyes as the same group publicly reported elsewhere as Geumseong121, Group123, ScarCruft, APT37, Reaper, and Ricochet Chollima, tracing its activity back at least five years and noting possible ties to a 2015 campaign called Operation ProgramsByMe. Its principal targets are North Korean defectors, human-rights activists, researchers, and journalists, with some cases involving military-related documents. Tradecraft centers on email and mobile-messenger spear-phishing carrying weaponized HWP documents that abuse an EPS scripting vulnerability, alongside malicious LNK, VBScript, and Office documents and a 2018 Flash zero-day. AhnLab has continued tracking the group's evolution, including LNK-delivered RokRAT backdoors that inject decoded payloads into PowerShell processes and exfiltrate victim data through cloud storage services such as pCloud and Yandex.

Associated with: Scarcruft
First seen: 2018-03 • Last seen: 2024-05

Ricochet Chollima, also known in industry reporting as APT37, Inky Squid, RedEyes, ScarCruft, and Reaper, is a North Korea-nexus threat actor group active since at least 2012 that has primarily targeted entities in South Korea while also striking organizations in Japan, Vietnam, the Middle East, and elsewhere, with a focus on chemical, electronics, manufacturing, aerospace, automotive, and healthcare verticals. Its toolset includes Windows UAC bypass techniques, HTTPS-based command and control, an MBR wiper, Flash exploits, steganography, and malware families such as RokRAT, Bluelight, and NavRAT. In 2024 the group used LNK files to distribute RokRAT and targeted Southeast Asian entities with VeilShell RAT as part of a campaign tracked as Shrouded Sleep, while also leveraging a Microsoft browser zero-day vulnerability. The group has also expanded into mobile espionage, distributing KoSpy, an Android spyware family that masquerades as utility applications, retrieves configuration data from cloud infrastructure to dynamically enable or disable itself, and collects SMS messages, call logs, location, files, and audio from Korean and English-speaking targets via Google Play and third-party app stores.

Associated with: Scarcruft
First seen: 2019-02 • Last seen: 2026-01

Ruby Sleet is Microsoft’s designation for a North Korean threat actor that the company has tracked since 2020. Microsoft publicly profiled the group under this name in November 2024, describing increasingly sophisticated phishing and software-compromise operations against aerospace, defense, satellite, and weapons-system targets. The actor researches victims’ environments, develops capabilities tailored to software they use, signs malware with legitimate certificates obtained from compromised organizations, and distributes backdoored virtual-private-network clients, installers, and other trusted applications. In December 2023, Ruby Sleet compromised a South Korean construction company and replaced legitimate VeraPort software with a malicious version that communicated with the group’s infrastructure. Microsoft assesses that theft of aerospace and defense technology could help North Korea improve its understanding of missiles, drones, and related systems, making intelligence collection and technology acquisition central objectives of the activity.

Associated with: Cerium
First seen: 2023-04 • Last seen: 2026-05

Sapphire Sleet is a North Korean state actor that Microsoft named in April 2023 under its weather-themed taxonomy, replacing an earlier internal codename; Microsoft's naming reference also links it to Genie Spider and BlueNoroff. Microsoft has separately assessed the actor as active since at least March 2020, targeting the financial sector, including cryptocurrency, venture capital, and blockchain organizations, with the goal of stealing cryptocurrency wallets and related intellectual property. Its core playbook is social-engineering-led: operators create fake recruiter personas on social media and professional networking sites, engage targets about job opportunities, and direct them to install software disguised as video-conferencing tools or SDK updates. On macOS this has evolved into a multi-stage AppleScript intrusion chain using cascading script-to-interpreter payload delivery, fake system password dialogs to harvest credentials, manipulation of macOS permission databases to bypass user consent, and persistence mechanisms, culminating in exfiltration of browser data, cryptocurrency wallets, messaging-app sessions, SSH keys, and notes. The group has also run large-scale software-supply-chain compromises, including poisoning more than 140 npm packages with a typosquatted dependency that deployed a dropper and follow-on backdoors.

Associated with: Copernicium
First seen: 2023-04 • Last seen: 2026-08

ScarCruft is a codename introduced by Kaspersky for an APT group first identified through Operation Daybreak, a March 2016 spear-phishing campaign that used a previously unknown Adobe Flash Player exploit to compromise more than two dozen high-profile victims in Russia, Nepal, South Korea, China, India, Kuwait, and Romania; the group was also linked to an earlier campaign, Operation Erebus, which used watering-hole attacks with a separate Flash exploit. Kaspersky assessed ScarCruft's tradecraft and tooling as professional and well above average for a group that had, at the time, managed to remain largely undetected. In subsequent Kaspersky reporting, ScarCruft, also referred to elsewhere as APT37 or Temp.Reaper, continued targeting North Korean defectors, journalists covering North Korea, and government organizations tied to the Korean Peninsula. One investigation found the group had compromised a victim's social media and email accounts to approach and spear-phish the victim's associates, deploying PowerShell, Windows, and Android malware that shared a common command-and-control scheme, with related activity traced back to at least mid-2020.

First seen: 2016-06 • Last seen: 2026-07

SectorA is NSHC Security’s umbrella designation for a collection of North Korean threat-actor subgroups pursuing state intelligence and foreign-currency objectives. NSHC’s 2019 activity review described at least seven subgroups, with SectorA01, SectorA02, and SectorA05 particularly active and SectorA06 and SectorA07 emerging in specific periods. Their targets included government ministries, public enterprises, political and diplomatic organizations, defectors and support groups, banks, cryptocurrency exchanges and holders, defense and military-related entities, and companies across Asia, Europe, the Middle East, Africa, and the Americas. SectorA campaigns commonly used spear-phishing with malicious Hangul, Word, Excel, script, executable, or multimedia files, supplemented by social engineering, credential phishing, watering holes, and vulnerability exploitation. Individual subgroups divided responsibilities between financial theft and collection of political, diplomatic, military, and strategic information, while adjusting malware and lure formats to target regions and sectors.

First seen: 2019-01 • Last seen: 2026-04

SectorA01 is a designation used by South Korean firm NSHC's ThreatRecon team, appearing as early as a January 2019 report analyzing a custom proxy utility tied to the group's activity against financial-sector targets worldwide. NSHC has tracked SectorA01 as one of several numbered "SectorA" subgroups that collectively pursue South Korean government and diplomatic, financial, and research-sector targets worldwide, chiefly via spear-phishing links, alongside exploitation of software vulnerabilities, including a 2023 3CX supply-chain compromise, and abuse of legitimate cloud services such as OneDrive for command-and-control. A November 2025 NSHC report, identifying SectorA01 as also known as Lazarus, details a May 2025 campaign against cryptocurrency users in which a fake Deriv trading-app installer launched a multi-stage, multi-language infection chain, an Electron/JavaScript stage mimicking the real Deriv site while covertly beaconing to an attacker server, a Python stage, and a final backdoor, that stole browser credentials, wallet files, and clipboard data, logged keystrokes, deployed AnyDesk for hands-on control, and used Tor-based command-and-control with defense-evasion tampering.

Associated with: Lazarus
First seen: 2019-01 • Last seen: 2025-11

SectorA02 is one of the SectorA subgroups tracked by NSHC. In its review of 2019 activity, NSHC described the subgroup as pursuing both intelligence collection and financial objectives. SectorA02 repeatedly targeted South Korean government agencies and organizations connected to political and diplomatic activity, seeking high-level information, while some campaigns targeted financial companies and cryptocurrency-related businesses. Its initial-access methods centered on phishing and spearphishing, using malicious Hangul Word Processor, Microsoft Word, and Excel documents selected for the intended victim. NSHC also observed simple phishing, malicious scripts, and more elaborate social engineering through KakaoTalk. During 2019 the subgroup broadened collection beyond South Korea toward political activity in Europe, North America, and Southeast Asia, while continuing campaigns against financial and cryptocurrency targets. The reporting depicts a flexible espionage-oriented group able to adapt lure formats, social channels, and targeting to operational priorities.

Associated with: Scarcruft
First seen: 2020-03 • Last seen: 2025-04

SectorA03 is a North Korean activity cluster within NSHC Security’s SectorA threat-actor taxonomy. In September 2024, NSHC observed the group operating against targets in Hong Kong and Germany. Its attack chain used a malicious DLL whose strings were protected with XOR and Base64 encoding. The DLL abused ImageView_Fullscreen, an exported function in the legitimate Windows Photo Viewer component shimgvw.dll, to support execution. The final-stage malware collected information about compromised systems and, depending on operational requirements, could receive and execute additional payloads from attacker-controlled infrastructure. NSHC places SectorA03 within a broader North Korean ecosystem whose persistent strategic objectives include collecting political and diplomatic intelligence related to South Korean government activity while also conducting globally distributed operations that can support acquisition of financial resources.

First seen: 2020-03 • Last seen: 2025-02

SectorA04 is one of several hacking groups NSHC's ThreatRecon researchers track under the SectorA naming scheme in their monthly Threat Actor Group Intelligence Reports, with SectorA04-specific activity confirmed by NSHC as early as April 2021. The group's operations have targeted South Korea, including spear-phishing emails sent to government agencies and North Korea researchers using lures such as fake portal account-verification notices and monthly North Korea trend reports, and watering-hole attacks that injected malicious scripts into public-institution websites to infect visitors. It has also attacked manufacturing, media, construction, and educational organizations in South Korea using Word-based malware and files disguised as OpenVPN client installers to fetch staged payloads from command-and-control servers, and compromised corporate central-management software to distribute malware. Its activity has extended beyond Korea as well, including ransomware attacks against small businesses in Germany and Hungary, and a fake-recruiter campaign in Italy and Colombia that delivered malicious PDF readers capable of remote command execution, file downloads, and data theft.

Associated with: Andariel
First seen: 2020-03 • Last seen: 2025-03

NSHC's ThreatRecon team tracks SectorA05 as one of several hacking groups operating under its broader SectorA grouping, consistently linked to politically motivated hacking against South Korea alongside financially motivated cryptocurrency theft intended to offset international sanctions. In a campaign NSHC named Operation Kitty Phishing, SectorA05 sent malware-laden, password-protected archives disguised as Hangul Word Processor documents to South Korean reporters covering Unification Ministry topics in January 2019, deploying parallel DLL-based and script-based remote access tools alongside long-running email credential-phishing operations targeting South Korean government, diplomatic, and defense personnel and Gmail users. The group used Google Drive to stage malware and configuration data and maintained a compromised Korean-domain command-and-control server continuously for more than 27 months. NSHC observed SectorA05 increasingly pivoting toward stealing cryptocurrency wallets and private keys from exchange employees, individual traders, and developers alongside its traditional espionage targeting, reflecting a dual mandate of intelligence collection and sanctions-evasion revenue generation.

Associated with: Kimsuky
First seen: 2019-01 • Last seen: 2025-07

SectorA06 is a North Korean activity cluster within NSHC Security’s SectorA threat-actor taxonomy. NSHC observed the group operating against macOS users in Austria during September 2024. The campaign distributed Mach-O malware disguised as Discord, a legitimate voice-over-IP application. Once installed, the malicious program replaced the victim’s existing Discord application so that it would launch automatically when the system started. It then created and executed additional malware that provided remote-control functionality over the compromised host. NSHC situates SectorA06 within a broader North Korean actor ecosystem whose long-running objectives include gathering advanced political and diplomatic information related to South Korean government activity while also pursuing globally distributed operations intended to secure financial resources. The observed campaign shows the cluster adapting trusted software impersonation and persistence techniques to macOS environments.

Associated with: Bluenoroff
First seen: 2020-03 • Last seen: 2025-02