Actors

249 actors

SectorA07 is a subgroup designation NSHC's threat intelligence team uses within its broader SectorA cluster of North Korea-linked hacking groups. NSHC first defined SectorA07 in May 2019 as a smaller subgroup carved out of the larger SectorA05 group, assessing it as active mainly for collecting financial information from companies in South Korea and Southeast Asia. Through mid-2019 the group used spear-phishing with Microsoft Word macro-laden documents, a departure from the HWP files favored by other SectorA subgroups, and by July 2019 had added Android-targeted mobile malware. NSHC reports SectorA07 activity expanding into Germany, Russia, France, Japan, Malaysia, China, Hong Kong, and Vietnam through 2020, with the group adopting COVID-19-themed lure documents delivered via malicious Word macro scripts that download further malware from hardcoded attacker infrastructure, and later mixing in HWP files carrying PostScript-based malware, alongside domain-registration email accounts tied to Korean and Russian webmail providers.

Associated with: Konni
First seen: 2020-03 • Last seen: 2025-04

SeedpuNK is a Kimsuky subgroup classification centered on the AppleSeed malware family. Reporting describes the cluster's movement toward Go-based malware, including newly identified tools connected to existing SeedpuNK malware, and frames the change as a strategy intended to improve stability, usability, and scalability.

Associated with: Kimsuky
First seen: 2024-10 • Last seen: 2024-10

Selective Pisces is Palo Alto Networks Unit 42’s designation for a North Korean threat group also identified in its reporting as Lazarus Group, ZINC, and APT-C-26. Unit 42 publicly used the name in September 2022 while describing threat-hunting results involving malicious unsigned DLLs. The group abused signed third-party software, including DreamSecurity MagicLine4NX, to launch malicious payloads and used DLL side-loading to evade detection. Its execution chain wrote a malicious DLL, copied the legitimate Windows Remote Management host process into a randomly named ProgramData directory, and relied on that trusted binary to load the payload. The actor also established persistence by placing a malicious DLL under a name expected by the Windows print-spooler service. This tradecraft combines legitimate-software abuse, search-order hijacking, encrypted or high-entropy payloads, nonstandard filesystem locations, and system-service execution to conceal North Korean operations.

Associated with: Lazarus
First seen: 2022-09 • Last seen: 2024-09

Volexity uses SharpTongue to track a North Korean threat actor whose activity is often lumped by other researchers under the broader Kimsuky label, though Volexity treats it as a distinct, well-documented cluster. SharpTongue primarily targets individuals and organizations in the United States, Europe, and South Korea working on North Korea policy, nuclear issues, and weapons systems, including journalists, government officials, academics, and think tanks, aiming to steal credentials and maintain persistent access to email and files. Its hallmark technique is patient social engineering: attackers build rapport through extended, non-malicious email exchanges, sometimes soliciting written papers or proposing fake in-person meetings, before delivering password-protected, macro-laden documents (often loading BabyShark VBScript malware) or credential-harvesting links. Since September 2021, Volexity has also observed SharpTongue deploying a malicious Chrome, Edge, or Whale browser extension it calls SHARPEXT, which, once a system is already compromised, directly inspects and exfiltrates Gmail and AOL webmail content from within the victim's logged-in browser session using a hidden DevTools-based mechanism, evading typical email-provider security alerts.

Associated with: Kimsuky
First seen: 2022-07 • Last seen: 2023-10

Silent Chollima is the name CrowdStrike introduced, as part of its nation-state adversary naming convention, for a North Korean state-sponsored threat actor. CrowdStrike first presented the name publicly in 2014, describing an operational window beginning in May 2011 and objectives spanning propaganda, disinformation, and disruption, with targeting of government, military, and financial institutions and tools including spearphishing, web exploitation, and social-media spamming. In a 2021 report, CrowdStrike's Falcon OverWatch threat hunters detailed a Silent Chollima intrusion against a pharmaceuticals organization, describing use of the penetration-testing tool Smbexec for stealthy lateral movement, the custom malware dropper Export Control, an information-stealing tool called GifStealer, and a remote-access tool named Valefor, along with anti-forensic techniques such as deleting and overwriting collected data and command history. CrowdStrike noted the group's evasiveness, attributing this partly to North Korea's restricted domestic internet use, which limits the exposure typically available to researchers profiling other nation-state actors.

Associated with: Andariel
First seen: 2014-04 • Last seen: 2026-01

Sleet is the weather-family suffix Microsoft uses for North Korean threat actors in its naming taxonomy. It is combined with a unique first word to form names such as Ruby Sleet, Sapphire Sleet, Pearl Sleet, Opal Sleet, Emerald Sleet, and Diamond Sleet; Sleet alone does not identify a single activity cluster.

First seen: 2023-04 • Last seen: 2025-06

Palo Alto Networks' Unit 42 tracks Slow Pisces as a North Korean state-sponsored threat group operating under the Reconnaissance General Bureau and believed to be a spin-off of the Lazarus Group. Active since around 2020, the group is primarily financially motivated, targeting large cryptocurrency-sector organizations to generate revenue for the regime, reportedly stealing over a billion US dollars from the sector in 2023 alone through fake trading applications, malicious packages, and software supply-chain compromises; later reporting also tied the group to large thefts from a Japan-based cryptocurrency company and a Middle East-based exchange. A dedicated 2025 Unit 42 report describes a campaign in which operators posed as recruiters on LinkedIn, sent benign job-description PDFs, then directed applicants to 'coding challenge' code repositories adapted from legitimate open-source projects. These repositories quietly fetched data from an attacker-controlled endpoint alongside legitimate sources, and validated targets received a payload via unsafe deserialization that installed custom malware for loading and stealing data, harvesting system, application, keychain, and cloud-credential information. The group has secondarily compromised aerospace, defense, and industrial organizations for espionage purposes.

Associated with: Jade Sleet
First seen: 2024-06 • Last seen: 2025-04

Palo Alto Networks Unit 42 tracks Sparkling Pisces as one of at least six North Korean threat groups operating under the Reconnaissance General Bureau, known elsewhere as Kimsuky, THALLIUM, and Velvet Chollima, and describes it as conducting intelligence collection while using cybercrime to fund espionage. Nicknamed by researchers as "the king of spear phishing," the group's most notable attack targeted Korea Hydro and Nuclear Power in 2014, and it initially focused on South Korean government agencies, research institutions, and think tanks before expanding to Western countries including the United States. Sparkling Pisces maintains complex, constantly evolving infrastructure that overlaps across multiple malware strains and campaigns, and it has masqueraded as legitimate Korean companies, including signing malware with a valid stolen certificate. Its arsenal continues to grow, including an undocumented keylogger called KLogEXE and an undocumented variant of the FPSpy backdoor, both linked through shared command-and-control infrastructure to a previously reported PowerShell keylogger deployed in spear-phishing campaigns against South Korean users.

Associated with: Kimsuky
First seen: 2024-09 • Last seen: 2026-05

Springtail is Symantec’s designation for the North Korean espionage group also known as Kimsuky. The group first drew public attention in 2014 after South Korea attributed an attack on Korea Hydro and Nuclear Power to it, and the United States has described it as a unit of the Reconnaissance General Bureau. Springtail initially specialized in South Korean public-sector targets and has used spear-phishing personas posing as journalists, academics, and East Asia specialists. Its campaigns increasingly abuse software supply chains and trojanized installers, including packages for TrustPKI, NX_PRNMAN, and Wizvera VeraPort. The group deploys information stealers and backdoors such as Troll Stealer, GoBear, BetaSeed, and the Linux Gomir backdoor, which support system discovery, command execution, file collection, persistence, proxying, and exfiltration. Its operations emphasize espionage against government-linked organizations and careful compromise of software likely to be installed by intended South Korean victims.

Associated with: Kimsuky
First seen: 2024-03 • Last seen: 2026-05

Squid Werewolf is a cyber-espionage cluster identified by BI.ZONE, which in December 2024 uncovered a phishing campaign impersonating an industrial organization's HR representative to lure targets with fake job offers, and attributed the activity to a cluster tracked elsewhere as APT37, Ricochet Chollima, ScarCruft, and Reaper Group. The campaign delivered a password-protected archive containing a malicious shortcut file disguised as a PDF job offer; opening it ran a command that decoded an embedded payload, copied a legitimate system utility into a startup folder to gain persistence, and side-loaded a custom, obfuscated loader through a code-injection technique. The loader checks internet connectivity and its own runtime duration to evade sandbox analysis, disables startup-folder autorun notifications, and either loads a locally cached, encrypted payload or fetches and decrypts one from its command-and-control server for execution in memory. BI.ZONE noted this activity closely resembles a previously reported cluster that used a similarly structured loader to deliver a remote access trojan.

Associated with: APT37
First seen: 2025-03 • Last seen: 2025-03

STARDUST CHOLLIMA is a designation used by CrowdStrike for a targeted-intrusion adversary assessed to have a likely nexus to North Korea, with community and industry reporting also linking the activity to the Lazarus Group and Bluenoroff. The adversary primarily targets financial institutions to generate liquid assets for the regime, including campaigns abusing SWIFT banking systems and strategic web compromises against global banking networks, and has also been suspected of targeting organizations in Latin America. It uses implants built on a shared code framework and employs code-protection tools, password-protected executables, and secure-deletion functions to evade detection and persist on compromised systems for extended periods; CrowdStrike has also noted technical overlaps between this actor's tooling and the WannaCry ransomware. In 2026, CrowdStrike attributed a supply-chain compromise of a widely used open-source software package to STARDUST CHOLLIMA with moderate confidence, based on updated cross-platform malware variants and infrastructure overlaps with the group's prior operations, reflecting a continued focus on currency generation through cryptocurrency theft and compromise of financial-technology software supply chains.

Associated with: Bluenoroff
First seen: 2018-02 • Last seen: 2026-08

Stonefly is Symantec’s designation for a North Korea-linked cyberespionage group also known as Andariel, BlackMine, Silent Chollima, and Operation Troy. Symantec reported in April 2022 that the group had operated since at least 2009 and was linked to the Reconnaissance General Bureau. Stonefly focuses on intelligence collection from high-value targets and has attacked government, military, defense, aerospace, telecommunications, energy, finance, and advanced-technology organizations. Its operators exploit public-facing servers, deploy web shells, harvest credentials, move laterally with legitimate administration tools, and use custom backdoors including Preft, NukeSped, and TigerRAT. The group has also conducted financially motivated intrusions, including attacks on banks and cryptocurrency exchanges, while maintaining a strong espionage mission. Stonefly campaigns show patient network exploration, targeted collection, custom malware deployment, and abuse of trusted tools to sustain access inside strategically valuable organizations.

Associated with: Andariel
First seen: 2022-04 • Last seen: 2024-10

Storm-0287 was Microsoft's temporary designation for an emerging activity cluster later named Jasper Sleet. Microsoft uses Storm identifiers for developing groups until it has sufficient confidence to assign or merge a durable actor name, and in June 2025 it stated that Jasper Sleet was formerly Storm-0287. The cluster conducts a North Korean remote-worker operation in which skilled technology workers obtain employment under false identities to generate revenue and support state interests. Operators create or procure identities, fabricate resumes and developer profiles, use staffing firms and facilitators, and conceal their locations through virtual private networks, proxy services, remote-management tools, and laptop farms. Their targeting expanded from United States technology, manufacturing, and transportation organizations to technology-related roles across industries worldwide. Access gained through employment can enable theft of source code, intellectual property, and trade secrets, as well as extortion. Microsoft also observed AI-assisted document and image manipulation and experimentation with voice-changing software.

Associated with: Jasper Sleet
First seen: 2023-04 • Last seen: 2025-06

Storm-0530 is a Microsoft developmental tracking designation for North Korean threat activity also known as DEV-0530 and H0lyGh0st. In Microsoft's taxonomy, Storm-numbered names are assigned to clusters that remain under development before a permanent weather-themed name is established.

Associated with: DEV-0530
First seen: 2023-04 • Last seen: 2023-04