Actors

249 actors

Storm-1789 was Microsoft’s temporary designation for the North Korean activity cluster that the company renamed Moonstone Sleet in May 2024. Microsoft initially observed the cluster overlapping with Diamond Sleet through reused Comebacker code and delivery of trojanized software over social media, but later separated it after the actor adopted bespoke infrastructure and conducted concurrent operations. Under its mature identity, the group pursued both espionage and revenue generation by creating fake software and blockchain companies, impersonating recruiters and developers, distributing malicious npm packages and trojanized applications, operating a weaponized tank game, seeking legitimate IT employment, and deploying FakePenny ransomware. It targeted software developers, education organizations, defense technology companies, drone manufacturers, and aircraft-parts companies. The transition from Storm-1789 to Moonstone Sleet therefore reflects Microsoft’s evolution from provisional activity tracking to recognition of a distinct and well-resourced actor.

Associated with: Moonstone Sleet
First seen: 2024-05 • Last seen: 2024-05

Datadog Security Research disclosed in August 2024 a malicious npm package cluster it internally designates Stressed Pungsan, following Datadog's practice of naming DPRK-nexus clusters after dog breeds native to North Korea. On July 7, 2024, an npm user published two malicious packages that copied a popular open-source Node.js configuration library and added a pre-install script which downloaded and executed, via a living-off-the-land binary, a malicious DLL retrieved from an attacker-controlled server. Datadog assessed that the tactics, techniques, procedures, and command-and-control infrastructure used in this campaign closely align with activity that Microsoft tracks as the North Korean actor Moonstone Sleet. The malicious packages were removed from the npm registry only hours after publication, a pattern Datadog noted this actor uses to publish quickly and evade detection, and the publishing account had no other prior packages. The campaign reflects continued DPRK-aligned abuse of open-source software supply chains, specifically npm, to gain initial access into developer and cloud environments.

Associated with: Moonstone Sleet
First seen: 2024-08 • Last seen: 2024-08

SuccessKey is Checkmarx Zero’s designation for the operator of ChainVeil, a malicious npm supply-chain campaign publicly described in June 2026. The actor used the npm account successkeyteck to publish at least nine typosquatted packages containing fourteen malicious versions, targeting JavaScript developers who searched for Tailwind, Sass, TypeORM, and rate-limiting libraries. Malicious code executed when applications imported a package rather than during installation, helping it evade scanners focused on lifecycle scripts. The loader copied metadata from legitimate projects, used layered obfuscation, checked for analysis environments, and resolved rotating payloads through transactions on Tron, Aptos, and Binance Smart Chain. Its final remote-access payload supported interactive shells, arbitrary command and JavaScript execution, file theft, SSH-key and npm-token collection, macOS Keychain access, and hidden persistence in shell configuration files. Infrastructure history indicated a sustained, automated operation beginning by June 2025.

Associated with: Polin Rider
First seen: 2026-06 • Last seen: 2026-07

Tencent's Yujian Threat Intelligence Center uses T-APT-15 as its internal tracking designation for the Lazarus Group, a North Korea-linked APT that Tencent describes as having a history of attacks against South Korea, the United States, and global financial institutions, including the Sony Pictures breach, the Bangladesh Bank SWIFT heist, cryptocurrency exchanges, and suspected links to WannaCry. In a 2018 report, Tencent documented T-APT-15/Lazarus spear-phishing cryptocurrency exchanges and other targets with decoy Word documents, themed around agreements, IT security, and exchange security analysis, that embedded a Flash exploit for CVE-2018-4878, a use-after-free vulnerability enabling arbitrary memory read and write. Successful exploitation injected shellcode into explorer.exe, which fetched further payloads from attacker-controlled infrastructure and ultimately deployed a variant of the FALLCHILL remote-access trojan, linked to Lazarus through code, command-dispatch, and protocol similarities as well as Korean-language RAT resources. Tencent assessed that the group's targeting had expanded from energy, military, and government sectors toward financial institutions, particularly cryptocurrency exchanges.

Associated with: Bluenoroff
First seen: 2018-03 • Last seen: 2018-03

TA-Ant is an illustrative example of AhnLab's threat-actor naming format rather than a documented standalone group. AhnLab uses arthropod names for sufficiently characterized actors, retains Larva-number identifiers when information is limited, and may place established industry names such as Lazarus alongside its own TA designation.

First seen: 2024-02 • Last seen: 2025-02

TA-RedAnt is the name used by AhnLab and South Korea’s National Cyber Security Center for the North Korean threat actor also known as RedEyes, ScarCruft, Group123, and APT37. Their October 2024 joint reporting attributed Operation Code on Toast to the group. TA-RedAnt has targeted North Korean defectors and specialists on North Korean affairs through spear-phishing email, malicious Android packages, and Internet Explorer vulnerabilities. In Code on Toast, the actor compromised a Korean online-advertising server and injected exploit code into advertisements rendered by desktop toast-notification software that still relied on Internet Explorer’s obsolete WebView engine. Exploitation of CVE-2024-38178 occurred without user interaction, downloaded malware to affected Windows systems, and enabled remote commands. The operation demonstrates the group’s willingness to compromise upstream content infrastructure and exploit unsupported browser components embedded inside otherwise legitimate applications to reach carefully selected victims.

Associated with: Red Eyes
First seen: 2024-10 • Last seen: 2026-06

Proofpoint, in a July 2022 report on state-aligned activity targeting journalists and media, described the North Korea-aligned actor TA404, known more broadly by researchers as Lazarus, targeting a US-based media organization in early 2022 with job-opportunity-themed phishing shortly after that organization published an article critical of North Korean leader Kim Jong Un. Consistent with TA404's typical pattern of beginning campaigns with benign reconnaissance before sending malware, the operation used recipient-customized URLs that impersonated a branded job-posting landing page; interacting with the link, which contained a unique target identifier, confirmed the email had been delivered and opened, and also collected identifying information about the victim's device. Proofpoint did not observe a follow-on malicious attachment in this instance but assessed one was likely, based on the actor's established behavior. Proofpoint also noted that Google's Threat Analysis Group disclosed related activity on March 24, 2022 as part of "Operation Dream Job," sharing overlapping indicators of compromise with the campaigns Proofpoint tracked, though journalism and media were not listed among the targeted sectors in Google's disclosure.

Associated with: Lazarus
First seen: 2022-07 • Last seen: 2022-07

Proofpoint tracks TA406 as a North Korea-aligned threat actor and one of several distinct actors that make up activity publicly tracked by others as Kimsuky, Thallium, and Konni Group; Proofpoint separately distinguishes TA406 from two related actors it designates TA408 and TA427. Proofpoint observed TA406 campaigns targeting its customers since 2018, with volume remaining low until activity increased sharply from January through June 2021, when the group conducted almost weekly credential-theft campaigns against foreign policy experts, journalists, and non-governmental organizations, alongside research, education, government, and media organizations more broadly. TA406 primarily relies on credential-harvesting phishing rather than malware, though two notable 2021 campaigns attempted to distribute previously undocumented implants for information gathering. Beyond espionage, the group engages in financially motivated activity, including cryptocurrency-focused campaigns and sextortion schemes, reflecting a threat actor that blends state-aligned intelligence collection with opportunistic criminal monetization.

Associated with: Konni
First seen: 2021-11 • Last seen: 2026-05

TA408 is one of three threat actors into which Proofpoint separates activity broadly tracked by the security community as Kimsuky, alongside TA406 and TA427. The designation reflects Proofpoint's own visibility and clustering of North Korea-aligned activity.

Associated with: Kimsuky
First seen: 2021-11 • Last seen: 2021-11

TA427 is one of three distinct threat-actor clusters, alongside TA406 and TA408, that Proofpoint separates out of the broader activity publicly known as Kimsuky; Proofpoint also refers to TA427 as Emerald Sleet, APT43, THALLIUM, or Kimsuky, and assesses it as a DPRK-aligned group working in support of the Reconnaissance General Bureau. TA427 conducts long-running social-engineering campaigns against foreign-policy experts, journalists, academics, and think-tank or NGO-affiliated individuals in the United States and South Korea, using benign 'conversation starter' emails about nuclear disarmament, sanctions, and bilateral policy to build rapport over weeks or months before seeking sensitive analysis or opinions; malware or credential harvesting is used only rarely, after extended engagement. Since 2023 the group has impersonated well-known think tanks, and since December 2023 has abused permissive email-authentication policies, typosquatted domains, and private-email spoofing to pose as these personas, later adding hidden tracking images in February 2024 for reconnaissance of target email activity.

Associated with: Kimsuky
First seen: 2021-11 • Last seen: 2025-07

TA430 appears in a YARA rule identifier used to track the North Korea-associated HazyLoad proxy tool in memory. The cited rule detects proxy-related strings in HazyLoad and uses the label APT_NK_TA430_HazyLoad_Mem; the source does not otherwise define TA430 as a standalone actor.

Associated with: Andariel
First seen: 2024-01 • Last seen: 2024-01

TA444 is Proofpoint’s designation for a North Korean state-sponsored group whose activity overlaps with APT38, BlueNoroff, BlackAlicanto, Stardust Chollima, and COPERNICIUM. Active in its cryptocurrency-focused form since at least 2017, the actor is primarily tasked with generating revenue for the North Korean government. It historically targeted banks and later concentrated on cryptocurrency companies, exchanges, bridges, and individuals. TA444 uses tailored job, investment, salary, and blockchain-themed lures delivered through email, LinkedIn, marketing platforms, cloud storage, and malicious files including LNK, ISO, VHD, MSI, CHM, and remote-template documents. Its malware ecosystem includes CageyChameleon, Astraeus, Cardinal, msoRAT, Rantankba, and other backdoors for profiling, persistence, credential collection, and theft. Proofpoint describes a highly adaptive operator that rapidly tests new delivery methods, reuses dedicated infrastructure, and combines social engineering, malware deployment, credential harvesting, and laundering mechanisms to obtain substantial financial returns.

Associated with: Crypto Core
First seen: 2023-01 • Last seen: 2026-04