Actors

249 actors

Google's Threat Intelligence Group documented the North Korea-linked cluster UNC5342 in an October 2025 report, describing its adoption, tracked since February 2025, of "EtherHiding" — storing and retrieving malicious payloads via read-only calls to smart contracts on public blockchains (BNB Smart Chain and Ethereum) — marking the first observed nation-state use of this technique. UNC5342 operates within a social-engineering campaign that Palo Alto Networks dubbed "Contagious Interview," using fake recruiters and fabricated companies to lure software and cryptocurrency developers with job offers, coding tests, and fake error-message prompts that trick victims into running malicious code. The infection chain uses the JADESNOW JavaScript downloader, which queries blockchain smart contracts to fetch a JavaScript variant of the INVISIBLEFERRET backdoor, enabling credential and cryptocurrency-wallet theft and remote access. A 2026 incident report aligning its findings with the Google-documented cluster described UNC5342 tradecraft expanding beyond job lures into a fake macOS software-update lure encountered through ordinary web browsing, deploying a backdoor, an infostealer, and a sideloaded malicious browser extension, backed by on-chain configuration contracts and exchange-funded wallet infrastructure.

Associated with: Contagious Interview
First seen: 2025-04 • Last seen: 2026-07

Mandiant tracks UNC577, also known as Temp.Hermit, as a cluster of North Korean cyber activity active since at least 2013 that has significant malware overlaps with other North Korean operators, with whom it is believed to share resources such as code and complete malware tools. While UNC577 activity has primarily targeted entities in South Korea, it has also targeted organizations worldwide. Mandiant assessed with high confidence that a separately tracked cluster, UNC2970, is in fact UNC577, noting that UNC2970 has conducted a job-recruitment-themed spear-phishing campaign against Western media and technology companies since June 2022 that overlaps with prior public reporting on "Operation Dream Job." This activity included social engineering targets on LinkedIn using fake recruiter accounts before shifting conversations to WhatsApp to deliver phishing payloads, and deployment of the PLANKWALK backdoor alongside other post-exploitation tooling that shares code with tools previously attributed to UNC577, illustrating the group's evolution from a South Korea-focused cluster into an actor with global reach against media and technology targets.

Associated with: TEMP.Hermit
First seen: 2023-03 • Last seen: 2023-03

UNC614 is Mandiant’s designation for the North Korean actor publicly associated with Andariel and DarkSeoul and assessed as part of the Reconnaissance General Bureau. Mandiant describes the group as distinct from other overlapping North Korean clusters and focused primarily on military, government, defense, aerospace, nuclear, and advanced research targets. Its strategic collection supports weapons-development and other research priorities, although the actor has also conducted self-funding cybercrime, including ransomware activity against healthcare organizations. In 2022, Mandiant linked UNC614 to QUINSTATUS malware delivered through a malicious document likely targeting a major pharmaceutical company; related analysis also identified the MARBLEROCK and SWEETPEA families. The broader cluster attacks foreign businesses, government agencies, financial infrastructure, private companies, and the defense industry. Its operations combine espionage, technology acquisition, tailored malware, and opportunistic revenue generation while retaining a strong focus on sensitive military and scientific information.

Associated with: Andariel
First seen: 2023-02 • Last seen: 2023-10

The Mandiant report tagged to this cluster describes it throughout under the public name APT43, a prolific North Korean cyber operator that Mandiant has tracked since 2018 and assesses with high confidence supports the Reconnaissance General Bureau's collection priorities. The group combines moderately sophisticated technical capabilities with aggressive spear-phishing and social-engineering campaigns against South Korean and U.S. government organizations, academics, and think tanks focused on Korean-peninsula geopolitical and nuclear-security issues, and has also targeted Japan and Europe; from October 2020 through October 2021 it notably shifted focus toward health and pharmaceutical-sector targets, likely in support of North Korea's pandemic-response priorities. The actor builds numerous fraudulent personas, including posing as journalists or think-tank analysts, to build rapport with targets and obtain strategic analysis directly, and also uses spoofed domains and stolen contact lists for credential harvesting. Beyond espionage, the group is assessed to fund itself through cybercrime, including stealing and laundering cryptocurrency, and has collaborated with other North Korean cyber operators, underscoring its role within the broader North Korean cyber apparatus.

Associated with: TEMP.Hermit
First seen: 2023-03 • Last seen: 2023-03

UNK_DeadDrop is Proofpoint's designation for a likely North Korea-aligned phishing cluster documented in a June 2026 report on campaigns observed between April and May 2026 that targeted developers at close to 100 organizations across finance, cryptocurrency, education, technology, and business-services sectors, sending over 250 emails in about six weeks, mostly to US-based targets. The campaign used recruitment, technical-assignment, code-review, Foundry-testing, and AI-payment-themed lures directing victims to actor-controlled GitHub and GitLab repositories built around realistic project themes; opening these projects in Visual Studio Code or Cursor silently triggered a hidden task that installed a malicious extension and, on Linux and macOS, deployed Go-based malware built on the open-source Overlord command-and-control framework, while Windows victims received a JavaScript and Python payload chain run inside the editor's own process. The malware stole cryptocurrency wallets, browser credentials, and OS keychain or keyring data, exfiltrating it as ZIP archives before cleaning up traces. Proofpoint assessed the cluster shares targeting and tradecraft with Contagious Interview but tracks it separately given distinct initial access, campaign volume, and infrastructure.

Associated with: Contagious Interview
First seen: 2026-06 • Last seen: 2026-06

UTA0040 is Volexity's tracking name for a suspected North Korean threat actor associated with the 3CX software supply-chain compromise disclosed in March 2023. The operation delivered malicious, vendor-signed updates through 3CX's normal automatic update process to Windows and macOS endpoints. On Windows, a compromised media library decoded and injected an initial payload that retrieved encrypted command-and-control information from files hosted in a public code repository. A second-stage stealer collected system details and browser history and returned the data to attacker infrastructure, apparently enabling further payload delivery to selected hosts. The macOS installer contained an analogous malicious library and an encoded server list. Infrastructure and repository evidence indicated preparation from late 2022, while detection reports appeared in March 2023. The campaign demonstrated broad initial distribution, cross-platform development, staged reconnaissance, and selective follow-on access through a trusted software channel.

Associated with: UNC4736
First seen: 2023-03 • Last seen: 2023-03

Unit 121 is listed in security reporting as one of the names associated with the broad Lazarus Group designation. Because organizations divide North Korean activity differently, the label may overlap with activity that other sources track as Lazarus Group or as one of its constituent clusters.

Associated with: Lazarus
First seen: 2020-11 • Last seen: 2020-11

Vedalia is a name used in Broadcom and Symantec reporting for a North Korean threat actor associated with Konni, APT37, ScarCruft, and Reaper. The group has targeted Southeast Asian organizations through spear-phishing and malicious Windows shortcut files. Observed campaigns concealed oversized LNK files behind double extensions and excessive whitespace, then used command-line scripts to locate PowerShell, extract embedded components, and execute payloads. In 2024, Vedalia activity delivered VeilShell, a previously undocumented PowerShell remote-access backdoor. The infection chain used a ZIP archive containing an LNK file, extracted a benign decoy and malicious DLL, and loaded JavaScript that retrieved the backdoor. VeilShell collected and exfiltrated system information, manipulated files and the Windows registry, created scheduled tasks, and maintained remote access. These campaigns emphasize deceptive document delivery, script-based execution, persistence, and covert collection from selected regional targets.

Associated with: Konni
First seen: 2024-04 • Last seen: 2024-10

Velvet Chollima, also tracked as Kimsuky, Thallium, APT43, Emerald Sleet, Springtail, and Black Banshee, is one of the North Korean threat actor groups given a Chollima family name under a naming convention used by CrowdStrike. A December 2024 recap describes it as a state-sponsored group thought to be an offshoot of Lazarus Group and associated with North Korea's Reconnaissance General Bureau, active since at least 2014 and focused on espionage against government employees, think tanks, academics, and human rights organizations, while also stealing cryptocurrency to fund its operations. Reported 2024 activity includes trojanized TrustPKI and NX_PRNMAN installers delivering Gomir and Troll Stealer malware, TRANSLATEXT malware used against South Korean academics, spear-phishing abusing weak DMARC policies, and use of the KLogEXE and FPSpy families. Separate reporting describes a campaign beginning January 2025 targeting South Korean officials, NGOs, and media organizations with spear-phishing PDFs redirecting victims to fake CAPTCHA pages that trigger malicious PowerShell commands, plus a distinct infostealer campaign using a trading-app lure to deliver a custom XenoRAT variant.

Associated with: Kimsuky
First seen: 2019-02 • Last seen: 2026-05

Trend Micro tracks Void Dokkaebi, also known as Famous Chollima, as a North Korea-aligned intrusion set that targets software developers and IT professionals with interests in cryptocurrency, Web3, and blockchain technology through fake recruiter job-interview lures on platforms such as LinkedIn, including through the fictitious company BlockNovas, whose domain was seized by the FBI in April 2025 after its automated interview process delivered Beavertail and Invisible Ferret-family malware. Void Dokkaebi's operations are partly routed through anonymization layers built on Russian IP ranges near the North Korean border, used alongside North Korean IT workers embedded abroad, and its primary objective is cryptocurrency theft, with occasional pivots to espionage when initial access does not yield stealable funds. A subsequent campaign showed the group evolving into a self-propagating supply chain threat: compromised developers' repositories were weaponized with auto-running VS Code task configurations and obfuscated, git history-tampering JavaScript injections that retrieved payloads including a DEV#POPPER RAT variant via blockchain transactions, infecting more than 750 public repositories and reaching organizational codebases.

Associated with: Contagious Interview
First seen: 2025-04 • Last seen: 2026-07

WASSONITE is a threat activity group designation used by Dragos in its industrial cyber threat landscape and Year in Review reporting.

Associated with: Lazarus
First seen: 2020-05 • Last seen: 2023-02

Whois Team is a name that emerged in March 2013 when attackers claimed responsibility for destructive "Dark Seoul" attacks against South Korean banks and broadcasters, defacing at least one victim website and deploying disk-wiping malware; contemporaneous reporting was initially unable to determine whether a nation-state was responsible. Later analysis connected Whois Team to a second group calling itself the NewRomanic Cyber Army Team, which claimed the 2013 attacks and left messages and imagery closely resembling those later used in the November 2014 Sony Pictures intrusion, contributing to the public case for North Korean responsibility for that attack as part of an espionage campaign researchers traced back to 2009. Separate research cautioned that the Whois Team name and its listed handles could represent a false flag, noting that a South Korean white-hat capture-the-flag team also uses the "WhoIs" moniker, and that no additional attacks under the Whois Team name were subsequently observed.

Associated with: Lazarus
First seen: 2013-03 • Last seen: 2014-12

Wagemole is a campaign name Palo Alto Networks' Unit 42 introduced in November 2023, tracked internally as CL-STA-0241, for North Korea state-sponsored threat actors who seek unauthorized remote employment with organizations in the United States and elsewhere, attributing the activity with high confidence to North Korea. Unit 42 discovered Wagemole infrastructure while investigating a related campaign it named Contagious Interview, which infects software developers with malware called BeaverTail and InvisibleFerret during fake job interviews to steal data later reused to build fraudulent identities; Wagemole operators use this stolen and purchased personal data, together with forged passports and driver's licenses, AI-assisted interview study guides, and automated job-application tooling on freelance platforms, to pass background checks and secure remote technical roles, often paid through services like PayPal to obscure financial trails. Subsequent research ties Wagemole proceeds to funding North Korean weapons programs and to specific individuals, and documents the operation adapting its personas' claimed locations, malware obfuscation, and persistence techniques over time while continuing to target banking, financial-services, and information-technology organizations.

Associated with: Famous Chollima
First seen: 2023-11 • Last seen: 2026-03