CTG-6459 is the identifier Secureworks Counter Threat Unit researchers use for a subgroup of the broader NICKEL ACADEMY North Korean activity cluster, which CTU assesses with high confidence focuses on acquisitive financial crime against financial institutions and cryptocurrency-related organizations for the North Korean government's benefit. The group's geographic scope is unusually broad among North Korean clusters, spanning victims in North and South America, Europe, Africa, and Asia, with an apparent preference for countries with weaker financial regulatory oversight. CTU traces the cluster's prominence to the February 2016 theft of roughly eighty-one million dollars from Bangladesh Central Bank via fraudulent SWIFT messages, followed by similar operations against banks in Vietnam, Ecuador, Taiwan, Chile, and India, and probable compromise of the Polish Financial Supervision Authority website in February 2017. Since at least 2018 the group has increasingly targeted cryptocurrency exchanges and decentralized-finance platforms using trojanized trading applications to steal wallet contents, including a 2022 campaign publicly named TraderTraitor. CTU assesses the group shares tooling with NICKEL ACADEMY, with malware ties to Operation Blockbuster and the Sony Pictures intrusion.
Actors
249 actors
S2W's Threat Analysis and Intelligence Center tracks ChinopuNK as an internally designated subgroup of the North Korean state-sponsored ScarCruft group, using the internal label "puNK" for partially unidentified North Korean threat actors; ChinopuNK had previously been linked to distribution of the Chinotto malware. In a campaign identified through August 2025, ChinopuNK used a malicious LNK file inside a RAR archive disguised as a South Korean postal-code update notice to deploy an AutoIt loader that fetched further payloads, including the NubSpy backdoor communicating over the PubNub messaging service, the PowerShell-based LightPeek stealer, the TxPyLoader Python loader, the previously documented FadeStealer exfiltration tool, VCD ransomware, and a Rust-based backdoor called CHILLYCHINO adapted from an earlier PowerShell version. The use of ransomware marked a notable departure from ScarCruft's historically espionage-focused operations, suggesting a possible shift toward financially motivated or disruptive objectives alongside continued reliance on real-time messaging platforms for command and control and ongoing efforts to port tooling to new programming languages for detection evasion.
CHOLLIMA is CrowdStrike's naming family for North Korean adversaries rather than one single actor. CrowdStrike reporting describes several distinct CHOLLIMA groups whose operations support DPRK espionage, destructive activity, and revenue generation, including economic espionage, tracking dissidents and defectors, and cryptocurrency-related theft.
Churihyang is the geographic naming component KrakenLabs uses for North Korean threat actors. The name is derived from the Korean term for Daphne odora, a fragrant but toxic plant, and is combined with a descriptive first word to create actor names such as the illustrative Aggressive Churihyang.
Microsoft first tracked this North Korea-nexus activity in December 2022 under the temporary designation DEV-0139, describing an operation in which the actor used cryptocurrency-focused Telegram groups to build trust with employees of a cryptocurrency investment firm before sending a weaponized Excel file that ultimately installed a backdoor; a related sample was distributed via a trojanized MSI installer for a fake application. An October 2023 analysis tied this DEV-0139 activity to the actor Microsoft names Citrine Sleet, consistent with Microsoft's practice of converting temporary DEV designations into named actors once attribution confidence is reached. In August 2024, Microsoft published a profile describing Citrine Sleet as a North Korea-based actor that primarily targets financial institutions and cryptocurrency organizations and individuals for financial gain, using fake trading-platform websites, fabricated job offers, and its AppleJeus trojan; the group also exploited a Chromium zero-day vulnerability to deploy the FudModule rootkit, sharing tooling with the related actor Diamond Sleet. Citrine Sleet is also tracked elsewhere as AppleJeus, Labyrinth Chollima, UNC4736, and Hidden Cobra, and has been attributed to Bureau 121 of North Korea's Reconnaissance General Bureau.
Clasiopa is a threat cluster identified by Symantec after it targeted a materials-research organization in Asia; at the time of reporting there was no firm evidence establishing the group's origin or the identity of any sponsor. The group relies on a distinct, largely custom toolset rather than commodity malware, centered on the Atharvan backdoor alongside a modified version of the publicly available Lilith remote access trojan, a file-listing and exfiltration tool called Thumbsender, and a custom proxy tool. Observed tradecraft includes likely initial access through brute-force attacks on public-facing servers, disabling of endpoint security software, clearing of system and event logs, and exfiltration of file listings via disguised archive files. Backdoor command-and-control traffic is disguised as legitimate software-update traffic and protected with a simple custom encryption scheme. Analysts noted possible false-flag indicators, including a Hindi-language mutex string and an India-referencing archive password, but assessed these could be deliberately planted misdirection rather than genuine attribution clues.
Contagious Interview is the name Palo Alto Networks' Unit 42 gave in November 2023 to an ongoing campaign, tracked internally as CL-STA-0240, that Unit 42 attributes with moderate confidence to a North Korea state-sponsored threat actor. Unit 42 found the activity, dating to at least December 2022, poses as employers offering software development jobs, luring victims through fake interviews into installing malicious npm packages hosted on GitHub; this delivers malware Unit 42 named BeaverTail, a cross-platform information stealer and loader, followed by a Python backdoor named InvisibleFerret, with an objective of cryptocurrency theft and establishing footholds for further attacks. Unit 42 has continued to track the campaign's evolution, including a cross-platform BeaverTail variant compiled with the Qt framework in mid-2024. Other researchers, including Datadog, have linked additional malicious npm packages and distinct threat-actor clusters, such as one Datadog separately named Tenacious Pungsan, to the same Contagious Interview activity targeting software and blockchain developers.
CoralSleet is Microsoft Threat Intelligence's name, formerly tracked as Storm-1877, for a North Korean state actor discussed in a March 2026 Microsoft blog on how threat actors operationalize AI. Microsoft observed Coral Sleet embedding AI across its intrusion lifecycle: using generative AI to shortcut persona-development reconnaissance, researching job postings, in-demand skills, and industry tools to build convincing fraudulent digital-worker personas for social engineering; using development platforms to rapidly build and refresh convincing, high-trust web infrastructure for staging, testing, and command-and-control; and using AI coding tools, including jailbroken LLMs, to accelerate iterative malware development and reimplementation. Microsoft also observed Coral Sleet using agentic AI tooling to automate an end-to-end workflow spanning fake company website creation, remote infrastructure provisioning, and payload testing and deployment, producing code exhibiting AI-assisted traits such as emoji status markers and conversational inline comments describing execution states.
CryptoCore is a campaign name coined by the Israeli firm ClearSky in a June 2020 report describing a roughly three-year-old operation against cryptocurrency exchanges in Israel, the United States, Europe and Japan in which attackers stole hundreds of millions of dollars worth of crypto wallets; other researchers who examined overlapping activity around the same time suspected a Russian or other Eastern European origin and described the group obtaining access to exchange employees' password manager accounts. The same overlapping activity was also described under related names including CryptoMimic and Dangerous Password, involving spear phishing that lured victims into downloading malicious files, VBS-based command-and-control scripts, and custom RATs and credential stealers. In May 2021, ClearSky published a follow-up report comparing indicators, malware code, and detection-rule matches across its own and other firms' research, concluding with medium-high confidence that the campaign was actually run by North Korea's Lazarus Group, a state-sponsored actor pursuing espionage and cryptocurrency theft, marking what ClearSky described as the first known Lazarus targeting of Israeli organizations.
CryptoMimic, also referred to in industry reporting as Dangerous Password, CageyChameleon, and Leery Turtle, is an APT actor that NTT Security has observed active since around March 2018. The group targets banks and finance-related organizations worldwide, particularly those connected to cryptocurrencies, with victims in Japan, Russia, Europe, and the United States; unlike many espionage-focused APT groups, its objective appears to be financial gain. Attacks typically begin with a tailored email or LinkedIn message containing a shortened link that leads to a password-protected decoy document bundled with a shortcut file; opening the shortcut silently launches a script that downloads further components from the group's command-and-control infrastructure. This delivers a staged VBScript remote access tool that profiles the victim and, if of interest, is followed by interactive access, credential theft, and deployment of additional executables. CryptoMimic takes extensive measures to limit exposure of its tools, including rapidly expiring download links, swapping malicious files for benign ones, and deleting infrastructure within about a week, and researchers observed the group launching over a dozen attacks in a single month.
DEV#POPPER is Securonix's tracking name for an ongoing social-engineering campaign likely associated with North Korean threat actors. The operators target software developers with fictitious job interviews and malicious code repositories that deliver remote-access malware. Later activity expanded support across Linux, Windows, and macOS and affected victims in South Korea, North America, Europe, and the Middle East.