Actors

249 actors

TAG-120 (Threat Activity Group 120) was Recorded Future Insikt Group's original name, later changed to PurpleBravo, for a North Korean-linked cluster documented in a February 2025 report on North Korean IT-worker fraud and related cyber operations. Insikt Group found the group overlaps with the "Contagious Interview" campaign, first documented in November 2023, which targets software developers, primarily in cryptocurrency, through fake recruiter personas and fraudulent job interviews that lead victims to download malicious "coding challenge" files. Its toolkit includes the BeaverTail JavaScript infostealer, the cross-platform Python backdoor InvisibleFerret, and the OtterCookie backdoor, first identified in December 2024. Between October and November 2024, Insikt Group observed the group targeting at least seven organizations, including a cryptocurrency market-making firm, an online casino, and a software-development company, using fabricated recruiter personas and front companies such as "AgencyHill99" advertised across LinkedIn, Telegram, Upwork, DoraHacks, and Intch, while managing command-and-control infrastructure through Astrill VPN.

Associated with: Purple Bravo
First seen: 2025-02 • Last seen: 2025-02

TAG-121 is an Insikt Group designation for a separate cluster of North Korean-linked activity operating a network of front companies across China. The companies imitate legitimate information-technology firms by copying substantial portions of their websites, creating additional deniability and helping operators embed themselves in global IT supply chains. The activity forms part of a broader fraudulent remote-employment ecosystem used to obtain revenue, access, and proprietary information from international organizations. Workers may secure positions under false identities, while front companies and facilitators make their employment histories and business relationships appear credible. This access creates an insider threat: operators can steal sensitive data, introduce backdoors, or support wider cyber operations. Insikt Group identified suspected front companies spoofing firms in China, India, Pakistan, Ukraine, and the United States and assessed that clusters such as TAG-121 would continue exploiting remote work to threaten intellectual property and technology supply chains.

Associated with: Contagious Interview
First seen: 2025-02 • Last seen: 2025-02

Recorded Future's Insikt Group uses Threat Activity Group 71 (TAG-71) to designate North Korea-aligned activity that closely overlaps with public reporting on APT38, also known as Bluenoroff, Stardust Chollima, and BeagleBoyz. TAG-71 infrastructure has been used to spoof financial institutions and venture capital firms in Japan, Vietnam, Taiwan, and the United States through lookalike domains and phishing lures, including a document posing as material from a Singapore-based venture capital firm and files referencing a Department of Justice cryptocurrency-mixer report that used template injection to reach command-and-control infrastructure. Recorded Future linked prior TAG-71 infrastructure to the publicly reported CryptoCore campaign used for malware delivery, phishing, and command and control, and observed reused IP addresses previously identified in a Kaspersky report on Bluenoroff activity. This pattern is consistent with North Korean state-sponsored groups' established use of financially motivated intrusions against cryptocurrency exchanges, banks, and payment systems to generate revenue for a government facing extensive international sanctions.

Associated with: Bluenoroff
First seen: 2023-06 • Last seen: 2024-01

TEMP.Hermit is Mandiant’s designation for a North Korean actor active since at least 2013 and commonly associated with activity broadly called Lazarus Group. Mandiant assesses that its operations represent Pyongyang’s effort to collect strategic intelligence supporting North Korean interests. The actor targets government, defense, telecommunications, and financial institutions worldwide, with espionage rather than cryptocurrency theft as its primary mission. Its activity overlaps with AppleJeus tooling, and Mandiant has observed broader sharing of tools, personnel, and targeting across North Korea’s cyber apparatus. During the COVID-19 pandemic, TEMP.Hermit-related resources also overlapped with APT43 activity in a temporary task-force-like cluster targeting healthcare and research organizations for treatment and vaccine information. This flexible operating environment complicates strict attribution, but TEMP.Hermit remains distinguished by long-running strategic collection against government, military, communications, and other high-value institutional targets.

Associated with: Lazarus
First seen: 2023-03 • Last seen: 2026-09

TEMP.Reaper is the name FireEye, now part of Mandiant, assigned to a suspected North Korean threat group it began publicly tracking in February 2018, after identifying it as the actor behind exploitation of an Adobe Flash zero-day distributed via malicious Office documents to South Korean targets that ultimately delivered the DOGCALL backdoor. FireEye observed TEMP.Reaper operators interacting directly with command-and-control infrastructure from IP addresses on North Korea's STAR-KP network in Pyongyang, and documented the group's use of a wiper malware family called RUHAPPY, distinct from its otherwise espionage-focused operations. Historically the group's targeting concentrated on the South Korean government, military, and defense-industrial base, with lure themes tied to Korean reunification and North Korean defectors, before expanding internationally in 2017 to targets in Japan, Vietnam, and the Middle East across a wider range of industry verticals including chemicals, electronics, manufacturing, aerospace, automotive, and healthcare. FireEye assessed with high confidence that the group operates on behalf of the North Korean government and aligned TEMP.Reaper with activity separately reported by other researchers as ScarCruft and Group123.

Associated with: Scarcruft
First seen: 2018-02 • Last seen: 2024-04

Datadog Security Research disclosed in October 2024 a malicious npm package cluster it designates Tenacious Pungsan, following Datadog's practice of naming DPRK-nexus clusters after dog breeds native to North Korea. In September 2024, Datadog identified three npm packages, backdoored copies of popular open-source authentication and blockchain-API libraries, that together had a few hundred downloads and contained an obfuscated variant of BeaverTail, a JavaScript infostealer and downloader first identified by Palo Alto Networks Unit 42 in late 2023. BeaverTail targets cryptocurrency wallets and stored browser and payment-card data, and downloads a second-stage Python backdoor known as InvisibleFerret. Based on shared command-and-control infrastructure, a reused server directory structure, and consistent malware behavior, Datadog attributed these packages with high confidence to the Contagious Interview campaign, an ongoing DPRK-linked operation that lures technology-industry job seekers into fake interviews where the malware is delivered as a fabricated interview task, indicating this npm supply-chain activity forms part of that broader campaign targeting individual software developers.

Associated with: Contagious Interview
First seen: 2024-10 • Last seen: 2024-10

Thallium is Microsoft’s former designation for a threat group believed to operate from North Korea. Microsoft publicly named the actor in December 2019 while announcing legal action that enabled the company to seize fifty domains used in its operations. Thallium targeted government employees, think tanks, university personnel, peace and human-rights organizations, and specialists working on nuclear-proliferation issues, primarily in the United States, Japan, and South Korea. The group researched individuals through social media and public directories, then sent personalized spear-phishing messages that redirected victims to credential-harvesting sites. After compromising accounts, operators searched email, contacts, and calendars and created forwarding rules to retain access to new messages even after password changes. Thallium also deployed malware including BabyShark and KimJongRAT to steal information, establish persistence, and receive further commands, combining account compromise with endpoint intrusion for sustained intelligence collection.

Associated with: Kimsuky
First seen: 2019-12 • Last seen: 2022-02

The FBI, CISA, and US Treasury introduced the name TraderTraitor in an April 2022 advisory for a North Korean state-sponsored group active since at least 2020, overlapping with activity industry researchers track as Lazarus Group, APT38, BlueNoroff, and Stardust Chollima. Its hallmark technique is spearphishing employees of cryptocurrency exchanges, DeFi platforms, trading firms, and blockchain-gaming companies, often through fake recruiter outreach or bogus pre-employment coding tests, to deliver trojanized cross-platform cryptocurrency applications or malicious code copied into a victim's repository. These payloads can enable theft of private keys and fraudulent blockchain transactions. US authorities later attributed several major thefts to this activity, including the Harmony Horizon Bridge theft, the 2024 DMM Bitcoin exchange theft following a fake GitHub coding test sent to a wallet-software employee, and the February 2025 Bybit exchange theft. A joint FBI, DC3, and Japanese National Police Agency advisory also noted that the activity is tracked as Jade Sleet, UNC4899, and Slow Pisces.

Associated with: Bluenoroff
First seen: 2022-04 • Last seen: 2026-07

UAT-10027 is a designation Cisco Talos uses for a threat actor behind an ongoing campaign, observed since at least December 2025, that targets education and healthcare organizations in the United States with a previously undisclosed backdoor Talos named Dohdoor. The multi-stage intrusion chain begins with likely phishing-delivered PowerShell and batch scripts that side-load a malicious DLL disguised as a legitimate Windows library, using living-off-the-land binaries and command-and-control infrastructure hidden behind reputable cloud services to evade detection. Dohdoor uses DNS-over-HTTPS to resolve its command-and-control domains, employs custom encryption for its payloads, and reflectively injects decrypted payloads, potentially including Cobalt Strike, into legitimate Windows processes while bypassing endpoint detection through system-call unhooking. Talos assessed with low confidence that UAT-10027 has a North Korea nexus, citing technical overlaps with a tool called Lazarloader used by the Lazarus Group, while noting the campaign's education and healthcare targeting diverges from Lazarus's more typical cryptocurrency and defense focus.

Associated with: Lazarus
First seen: 2026-02 • Last seen: 2026-02

UAT-4820 is Cisco Talos’ designation for the espionage actor it also calls LilacSquid. Talos described the cluster in May 2024 after observing compromises dating from at least 2021 against organizations in pharmaceuticals, oil and gas, and technology sectors in the United States, Europe, and Asia. The actor gained access by exploiting vulnerable public-facing applications or by using compromised remote-desktop credentials. It then deployed open-source tools such as MeshAgent and customized versions of QuasarRAT, before introducing a proprietary loader named InkLoader and the PurpleInk remote-access trojan. The tradecraft showed overlap with North Korean activity tracked as Andariel, including use of the same SOCKS proxy and tunneling tool. UAT-4820’s small victim set, deliberate infrastructure, multiple access routes, tunneling, system discovery, and layered malware deployment indicate a patient campaign focused on maintaining covert access to strategically valuable organizations.

Associated with: Lilac Squid
First seen: 2024-05 • Last seen: 2024-06

Cisco Talos, the naming company, first documented UAT-5394 in an August 2024 report, later corroborated by a September 2024 blog post from another researcher summarizing the same findings and malware samples. Talos describes UAT-5394 as a North Korean state-sponsored nexus of threat actors developing and distributing MoonPeak, a remote access trojan forked from the open-source XenoRAT project; an earlier variant of this activity was first disclosed by AhnLab in a spear-phishing campaign that Talos assessed evolved into MoonPeak. Talos observed tactical and infrastructure overlaps with the Kimsuky group but stated it lacked sufficient technical evidence to confirm a link, so it tracks UAT-5394 as an independent cluster pending further intelligence. In mid-2024 the actor shifted from hosting payloads on legitimate cloud storage to servers it owned and controlled, likely to avoid takedowns, and Talos mapped an extensive network of staging servers, command-and-control servers, and dedicated virtual machines used to test MoonPeak implants before deployment. MoonPeak was observed evolving iteratively, adding obfuscation and pairing specific malware builds to specific C2 server versions to block unauthorized or rogue connections.

Associated with: Kimsuky
First seen: 2024-08 • Last seen: 2024-09

Interlab, a Seoul-based non-profit, has tracked UCID902 since 2021 as an advanced persistent threat cluster conducting watering-hole credential-harvesting campaigns against human rights activists and organizations advocating for North Korean human rights and Korean unification. The group compromises legitimate South Korean business and institutional websites, often ones built by a single shared web-development company, to host phishing pages that mimic Naver login pages, using lures disguised as Naver security alerts or official notifications; a validation check on the phishing kit redirects non-target visitors to the legitimate Naver site to reduce detection. Documented cases include phishing pages hosted on a law firm's website and on multiple medical research institution websites sharing common infrastructure. Interlab notes infrastructure and capability overlaps with the Kimsuky threat group, including a campaign using a malicious HWP document with lure themes referencing North Korea's Ministry of Unification, and states the group's motivations and targeting closely resemble those of North Korea-based threat actors, while cautioning that confidence in a specific North Korean attribution remains moderate given limited corroborating data points.

Associated with: 금성121
First seen: 2023-04 • Last seen: 2025-02

UNC1069 is Google Threat Intelligence Group’s designation for a financially motivated actor assessed with high confidence to have a North Korean nexus. Active since at least 2018, the group shifted toward Web3 targets by 2023, including cryptocurrency exchanges, financial-software developers, venture-capital firms, technology companies, and wallet and payment providers. Its operators compromise trusted messaging accounts, impersonate executives, arrange fake Zoom meetings, and use ClickFix-style troubleshooting instructions to convince victims to execute malware. A 2026 intrusion combined a reported deepfake video with macOS backdoors, downloaders, and data miners including WAVESHAPER, HYPERCALL, HIDDENCALL, SUGARLOADER, DEEPBREATH, CHROMEPUSH, and SILENCELIFT. These tools harvested Keychain credentials, browser passwords, cookies, Telegram data, notes, files, screenshots, and keystrokes while establishing persistence and hands-on-keyboard access. The group uses collected data both for direct cryptocurrency theft and to enable further tailored social engineering.

Associated with: Crypto Core
First seen: 2023-04 • Last seen: 2026-09