Actors

249 actors

Andariel is a threat group that the Korean Financial Security Institute designated as a subgroup of Lazarus, as Kaspersky reported in 2021. AhnLab described it in 2018 as active since 2015 and linked its activity to earlier operations against South Korean organizations. Its targets span military and defense bodies, political organizations, security and technology companies, energy research, banks, cash machines, cryptocurrency exchanges, and other financially relevant businesses. Characteristic access methods include spear-phishing documents with macros, watering holes that exploit locally used ActiveX software, attacks on centralized management products, and supply-chain compromise. By 2018 it was also expanding reconnaissance beyond Internet Explorer, collecting browser and software details from compromised Korean websites. Activity observed from 2020 into 2021 showed further evolution toward staged in-memory loaders, interactive backdoor use, and selectively deployed custom ransomware, combining intelligence collection with direct financial gain.

First seen: 2017-07 • Last seen: 2026-09

Appleworm is a name Symantec first listed in its April 2017 Internet Security Threat Report as an alias for Lazarus Group among a set of profiled nation-state threat actors. Two years later, in September 2019, the US Treasury's Office of Foreign Assets Control sanctions designation likewise listed Appleworm as one of many aliases used for Lazarus Group, describing it as a North Korea state-sponsored malicious cyber group based in Pyongyang, alongside separately designated North Korean-linked entities Andariel and Bluenoroff, also known as APT38. In February 2021, Symantec again referred to the actor as Lazarus, also known as Appleworm, while reporting on a US Department of Justice indictment charging three North Korean nationals with a string of financially motivated cyberattacks that stole approximately 1.3 billion dollars from financial institutions and cryptocurrency exchanges around the world.

Associated with: Lazarus
First seen: 2017-04 • Last seen: 2021-02

BABYLONGROUP is a cluster name introduced by the research group Chollima Group in an August 2025 post that began by pivoting off Kaspersky and Microsoft reporting on Moonstone Sleet's DeTankZone fake cryptocurrency-game campaign into its "legitimate" predecessor project, DefiTankLand. Investigating DefiTankLand's development team and related GitHub accounts, including ones tied to a "Galaxy Foundation"/BabylonSwap organization, the researchers clustered DPRK IT workers who focus on self-created web3/blockchain freelance projects, at times acting as CTOs while installing fabricated or recruited front-persons as CEOs; one non-DPRK Chinese national in the cluster also administers a Chinese cybercrime marketplace. A September 2025 follow-up traced a related persona to Bells Inter Trading Ltd, a suspected North Korean front company operating under Tanzanian work permits in Dar es Salaam that published a portfolio of mobile VPN and game apps totalling roughly 12 million installs, generating revenue while overlapping with the same DeTankZone investigation.

Associated with: Moonstone Sleet
First seen: 2025-08 • Last seen: 2025-09

The U.S. government tracks BeagleBoyz as a North Korean hacking team, an element of the Reconnaissance General Bureau, that overlaps to varying degrees with groups tracked elsewhere as Lazarus, APT38, Bluenoroff, and Stardust Chollima, and represents a subset of the broader Hidden Cobra activity. Likely active since at least 2014, BeagleBoyz conducts well-planned, disciplined bank robberies rather than typical cybercrime, and has attempted to steal nearly two billion dollars since 2015 through fraudulent ATM cash-out schemes and abuse of compromised bank SWIFT terminals, including the 2016 theft of eighty-one million dollars from Bangladesh Bank. The group has targeted financial institutions across dozens of countries in Africa, Asia, Europe, and the Americas, gaining initial access through spearphishing, watering holes, exploitation of internet-facing applications, and stolen credentials, sometimes obtaining footholds through third-party criminal groups. BeagleBoyz has also deployed destructive wiper and anti-forensic tools against victim banks to disrupt operations and conceal fraudulent transactions, generating revenue believed to fund North Korea's weapons programs.

Associated with: Bluenoroff
First seen: 2020-08 • Last seen: 2021-03

PwC publicly profiled Black Alicanto in September 2021 as an emerging North Korea-based threat actor focused on cryptocurrency theft. Its targeting broadened from cryptocurrency-wallet heists to venture-capital and investment firms around the world, using spearphishing, malicious documents, and attacker-controlled infrastructure. By 2022, PwC described the group using recruiter personas and job-themed lures, with archives containing shortcut files that invoked command execution and MSHTA to retrieve remote content. The group used double extensions and spoofed Google and other cloud services to make its delivery chain appear legitimate. PwC also observed Black Alicanto deploying successive script-based backdoors, showing an evolution from socially engineered initial access into multi-stage execution in financially motivated operations.

Associated with: Crypto Core
First seen: 2021-09 • Last seen: 2023-04

Black Artemis is an internal tracking name PwC introduced in a September 2020 conference presentation on the Dtrack remote-access trojan, explaining why it treats North Korea's Lazarus Group together with the related actor Andariel as a single cluster; PwC tied the two together through shared tooling, including Dtrack, traced back to 2014 and previously seen under other names, and a dropper family PwC calls TrackDrop, and described the cluster's activity as spanning breaches of financial institutions worldwide, aerospace-sector organizations, and the Kudankulam Nuclear Power Plant. Later PwC material from 2021 and 2022 continued using the label, describing Black Artemis, also referenced as temp.Hermit, as a persistent recruiter-themed social engineering operator that sends fake job offers with malicious attachments to targets in the aerospace, defense-industrial-base and manufacturing sectors as part of broader North Korean revenue-generation activity, and distinguished it from two other, separately tracked North Korean cryptocurrency-focused actors, Black Alicanto and Black Dev 2.

Associated with: Lazarus
First seen: 2020-03 • Last seen: 2023-04

Black Banshee is PwC's tracking name for the North Korea-based cyber espionage group more widely known as Kimsuky. PwC's 2019-2020 analysis grouped the group's operations into interlinked activity clusters connected by shared infrastructure, tooling, and tradecraft rather than isolated campaigns. One cluster traced a continuous effort from earlier publicly reported operations through a remote access trojan PwC called WildCommand, targeting the South Korean government, aerospace and defense contractors, and cryptocurrency organizations, before resurfacing against financial-sector entities in South East Asia. A second cluster, known elsewhere as BabyShark, persistently targeted policy and national-security think tanks and government bodies in the United States, South Korea, and Europe, and was assessed to continue in later reporting under different public names. The group also ran credential-harvesting operations against government departments and, separately, against a United Nations human-rights body, and introduced additional malware families over time. PwC assessed that Black Banshee's tradecraft, infrastructure reuse, and consistent targeting reflected a coordinated, strategically driven espionage mission that showed no signs of slowing.

Associated with: Kimsuky
First seen: 2020-02 • Last seen: 2026-05

PwC publicly profiled Black Dev 2 in September 2021 as an emerging North Korea-based threat actor hunting cryptocurrency and running the continuing Operation Gold Hunting campaign. The group formed part of a financially motivated activity set whose focus expanded from cryptocurrency-wallet heists to venture-capital and investment firms across multiple regions. PwC characterized its access activity through spearphishing themes and highlighted the malicious documents and infrastructure used in its campaigns. This combination of targeted social engineering, document-based delivery, and purpose-built supporting infrastructure was intended to compromise organizations connected to cryptocurrency and investment activity. At the time of publication, PwC noted that Black Dev 2 had received little open-source coverage, making the label a vendor-specific tracking name rather than a broadly defined public actor identity.

Associated with: Bluenoroff
First seen: 2021-09 • Last seen: 2023-04

Bluenoroff is Kaspersky's name for a financially motivated unit within the broader Lazarus formation. Kaspersky introduced the designation publicly in 2017 while documenting bank intrusions connected to the 2016 Bangladesh Central Bank theft and other attacks on financial institutions and SWIFT-connected systems. The group used watering holes, backdoors, compromised infrastructure, and malware tailored to banking environments, with activity spanning multiple countries. By 2022, Kaspersky described a shift from banks and SWIFT servers toward cryptocurrency businesses as the group's principal source of illicit income. Operators created convincing cryptocurrency software companies and applications, delivered backdoored updates, and used malicious documents and social engineering to abuse trust. The reporting portrays Bluenoroff as able to draw on the larger formation's malware, exploits, and infrastructure while maintaining a distinct financial objective.

First seen: 2017-04 • Last seen: 2026-07

Bureau 121 is listed in security reporting as one of the names associated with the broad Lazarus Group designation. Because organizations divide North Korean activity differently, the label may refer to activity that other sources track as Lazarus Group or as one of its constituent clusters rather than to a consistently isolated actor.

Associated with: Lazarus
First seen: 2015-12 • Last seen: 2020-11

CL-STA-0240 is Unit 42's tracking identifier for Contagious Interview, a North Korea-linked campaign active since at least December 2022. Its operators pose as prospective employers and approach software developers through job platforms and other communications channels, then use technical interviews to convince victims to run malicious packages or applications. The campaign has delivered BeaverTail and InvisibleFerret across Windows and macOS and is assessed as supporting cryptocurrency theft and follow-on access.

Associated with: Contagious Interview
First seen: 2023-11 • Last seen: 2024-10

Dragos tracks Covellite as a threat group that compromises networks associated with civilian electric energy organizations worldwide, gathering intelligence on intellectual property and internal industrial operations, though it lacks industrial-control-system-specific capability. Covellite operates globally with targets primarily in Europe, East Asia, and North America. U.S. targeting emerged in September 2017 through a small, targeted phishing campaign against select electric companies, using emails disguised as resumes or invitations that carried malicious Microsoft Word documents delivering a remote access tool used for reconnaissance and persistent, covert access. Covellite's infrastructure and malware show similarity to tooling associated with the group known as Lazarus and Hidden Cobra, with technical analysis indicating an evolution from known Lazarus toolkits, although Dragos notes it is not established how the two groups' capabilities and operations are otherwise related. Covellite later appeared to abandon North American targeting while remaining active in Europe and East Asia, and Dragos considers it a primary threat to the industrial control systems sector given its infrastructure-focused interest and improving capabilities.

Associated with: Black Artemis
First seen: 2018-05 • Last seen: 2018-05

SecureWorks' Counter Threat Unit tracks this activity as CTG-2460, one of several designations researchers use for a broader North Korean cluster the company calls Nickel Academy, encompassing cyber operations run by North Korea's Reconnaissance General Bureau that are not attributed to specific subgroups. The activity has been observed since at least 2009, initially concentrated on South Korean government and commercial targets, and gained wider notoriety for the November 2014 attack on Sony Pictures. While South Korea remains a primary focus, targeting has expanded globally to government agencies, think tanks, financial institutions, transportation and utility companies, non-governmental organizations, cryptocurrency exchanges, and defense contractors. Operators rely on customized malware delivered mainly through spearphishing, along with malicious software disguised as legitimate applications, sometimes signed with stolen certificates, and distributed denial-of-service operations. Tooling is routinely reworked, producing new malware variants or families that reuse components from earlier tools, and the group has also carried out isolated destructive attacks alongside ongoing espionage and financial operations.

Associated with: Nickel Academy
First seen: 2020-09 • Last seen: 2020-09
First seen: Jul 2017
Last seen: Sep 2026