Actors

249 actors

Microsoft tracked DEV-0139 as a temporary designation for an emerging cluster of threat activity, its convention for tracking an unknown or developing actor until enough evidence supports converting the label to a named actor. Microsoft documented an attack in which the threat actor joined Telegram groups used by cryptocurrency exchange VIP clients, identified a target investment company, and posed as representatives of a rival exchange to build trust before creating a secondary chat and requesting feedback on exchange fee structures. In October 2022, the actor sent a weaponized Excel file containing accurate fee-comparison data whose macro dropped a second encoded spreadsheet, which downloaded an image file split into a legitimate application, a malicious proxy DLL, and an XOR-encoded backdoor that were combined via DLL side-loading to grant remote access. Microsoft also identified a related MSI installer posing as a cryptocurrency dashboard application using the same DLL side-loading and proxying technique, dated June 2022, suggesting other campaigns run by the same actor using consistent tradecraft against the cryptocurrency industry.

Associated with: Citrine Sleet
First seen: 2022-12 • Last seen: 2022-12

DEV-0530 is a North Korea-based threat group first documented by Microsoft's MSTIC in a July 2022 report, which had tracked the group developing and using H0lyGh0st ransomware since June 2021, with confirmed victim compromises beginning around September 2021 (Microsoft later renamed the group Storm-0530 under an April 2023 weather-themed taxonomy update). The group primarily pursues financial objectives, encrypting victim files after exfiltrating data, then demanding Bitcoin payment while threatening to publish stolen data if victims refuse to pay; it operates a Tor-based site for victim communication. Victims were mainly small and midsize businesses across multiple countries, including manufacturing firms, banks, schools, and event-planning companies, suggesting opportunistic targets of opportunity; the group has been observed exploiting a web application remote-code-execution vulnerability for initial access, without use of zero-days. MSTIC assessed likely connections between DEV-0530 and the North Korean group PLUTONIUM, including shared infrastructure, communications, and tooling, though operational tempo and targeting differences suggest they remain distinct groups; activity timing was consistent with North Korean time zones.

Associated with: Plutonium
First seen: 2022-07 • Last seen: 2022-11

DarkPlum is an NTT Security Holdings tracking name for a highly active cyber-espionage group linked in its research to the Democratic People's Republic of Korea. NTT described the group publicly in 2024 as combining technical capability with effective social engineering. Its reported targets include government agencies, military organizations, academics, and think tanks in South Korea, Japan, Europe, and the United States. Alongside intelligence collection, the group conducts cryptocurrency theft to finance its activity. NTT's investigation identified phishing campaigns against South Korean academics and think tanks, as well as phishing pages intended to steal cryptocurrency-platform accounts. The group manages a layered operational infrastructure that includes VPN services, intermediate systems, and command-and-control servers, measures intended to strengthen operational security. Analysis of that infrastructure also supported assessment of operational locations, working patterns, and the scale of its campaigns.

Associated with: Kimsuky
First seen: 2024-10 • Last seen: 2025-04

Positive Technologies identified this activity in October 2022 after investigating an intrusion at a Russian industrial enterprise, where it found a previously unseen modular backdoor it named MataDoor, and named the operator Dark River after the word River found in phishing-document author metadata. The likely initial vector was a phishing email with a DOCX attachment exploiting a Microsoft MSHTML vulnerability, sent to Russian defense-industry organizations in August and September 2022; researchers linked this wave to a similar September 2021 campaign using the same vulnerability and identical URL-encoding technique against Russian defense and government targets, indicating the actor has operated since at least 2021. Payloads and later backdoor samples were signed with Sectigo certificates and used Namecheap-registered command-and-control domains that did not overlap between victims. MataDoor is built around a kernel and functional and network plugins, uses AES-encrypted configuration data, and disguises its files as legitimate software already present on infected hosts. Kaspersky separately linked a related backdoor variant to Lazarus group activity, though Positive Technologies could not independently confirm the operator's identity.

Associated with: Jade Sleet
First seen: 2023-09 • Last seen: 2023-09

ESET researchers named DeceptiveDevelopment in a February 2025 report on a North Korea-aligned cluster active since at least November 2023, noting overlap with earlier public reporting under the names Contagious Interview and DEV#POPPER. Posing as recruiters on LinkedIn, Upwork, Freelancer, and crypto-focused job boards, operators lure freelance software developers, especially those in cryptocurrency and Web3 projects, into fake coding tests and interviews that deliver trojanized GitHub, GitLab, or Bitbucket repositories, or cloned video-conferencing software. Victims on Windows, Linux, and macOS are compromised chiefly to steal cryptocurrency wallets and browser-stored credentials, with a possible secondary espionage aim. Core tooling includes the BeaverTail infostealer/downloader and modular Python InvisibleFerret RAT, later joined by OtterCookie, the multiplatform WeaselStore infostealer, the TsunamiKit toolkit, and more advanced backdoors such as Tropidoor and AkdoorTea that share code with malware linked to Lazarus. Subsequent reporting documented added ClickFix social-engineering lures, abuse of IDE task-runner files in VS Code and Cursor for delivery, and information-sharing ties to North Korean fraudulent IT-worker schemes tracked separately as WageMole.

Associated with: Contagious Interview
First seen: 2025-02 • Last seen: 2026-05

Microsoft tracks this actor as Diamond Sleet, the name it adopted in April 2023 for the North Korea-based group formerly designated ZINC, which other researchers have linked to activity described as Labyrinth Chollima, Lazarus, and Temp.Hermit. The group is assessed to pursue espionage, theft of personal and corporate data, financial gain, and destructive attacks against corporate networks, targeting media, information technology services, and defense organizations worldwide. Microsoft has reported its targeting of security researchers, weaponizing of open-source software, and a supply chain compromise of a German software provider. In October 2023 it exploited a JetBrains TeamCity remote-code-execution vulnerability to deploy a custom backdoor and DLL search-order-hijacking payloads that established command-and-control channels and dumped credentials from memory. The following month it distributed a trojanized installer for a legitimate CyberLink Corp. application, signed with a valid certificate and hosted on CyberLink's own update infrastructure, compromising over one hundred devices across Japan, Taiwan, Canada, and the United States. The group relies on malware built exclusively for its own use and has a history of exfiltrating data and compromising software build environments.

Associated with: Zinc
First seen: 2023-04 • Last seen: 2024-02

Earth Imp is Trend Micro's designation for a North Korean threat actor whose activity Trend Micro identifies as corresponding to the group tracked elsewhere as Konni. In research on the widespread exploitation of a Windows shortcut file vulnerability used for hidden command execution, Trend Micro's Zero Day Initiative found that Earth Imp was among the state-sponsored groups, primarily North Korean, that abused the flaw for cyber espionage and data theft in campaigns dating back to 2017. Trend Micro observed that Earth Imp crafted unusually large malicious shortcut files, padded with substantial whitespace and junk content, to conceal malicious command-line arguments from victims and evade detection, a technique also used by other North Korea-linked groups such as Earth Manticore. The exploitation of this vulnerability by North Korean actors formed part of a broader pattern of tool and technique sharing observed across North Korea's cyber program.

Associated with: Konni
First seen: 2025-03 • Last seen: 2026-04

Trend Micro's Japan unit named this actor Earth Kumiho, equating it with Kimsuky, in a May 2022 report analyzing domestic targeted attacks observed in Japan during 2021. The company identified Earth Kumiho as one of four targeted-attack groups it tracked operating against Japanese organizations that year, describing its focus as individuals connected to defense and diplomatic affairs. Trend Micro reported finding traces consistent with a suspected watering-hole style attack against a domestic target, though it noted that sustained, continuous targeting of Japanese organizations had not been confirmed at the time of publication and that its assessment also drew on attack patterns observed against similar targets outside Japan.

Associated with: Kimsuky
First seen: 2022-05 • Last seen: 2026-04

Earth Manticore is Trend Micro's Zero Day Initiative designation, equated with APT37, discussed in a March 2025 ZDI report on widespread in-the-wild exploitation of a Windows Shortcut (.lnk) vulnerability, ZDI-CAN-25373, which Microsoft declined to patch. The flaw lets attackers hide malicious command-line arguments inside .lnk shortcut files so they are not visible when a victim inspects the file's properties. Among roughly a dozen state-sponsored groups from North Korea, Iran, Russia, and China found abusing this flaw, ZDI singled out Earth Manticore, alongside the North Korea-linked Earth Imp (Konni), for crafting unusually large, whitespace-padded .lnk files, with a median size around 33 megabytes and samples up to roughly 55 megabytes, to further frustrate detection and analysis. The report situates this technique within a broader wave of exploitation, dating to 2017, by intrusion sets primarily pursuing espionage and data theft against government, financial, telecommunications, and defense-related organizations worldwide.

Associated with: APT37
First seen: 2025-03 • Last seen: 2026-04

The Security Alliance (SEAL) identified Elusive Comet as a threat actor running an ongoing social-engineering campaign against cryptocurrency users designed to install malware and steal funds, responsible for millions of dollars in losses. The group operates a fabricated venture capital persona, Aureon Capital, along with related entities including a press outlet and a podcast, maintaining polished websites and active social media profiles, sometimes impersonating real people with notable credentials, to establish an extensive and convincing online presence. Elusive Comet typically initiates contact with prospective victims over social media direct messages or email, inviting them to appear as podcast guests, then schedules a video call, often withholding details until the last minute to create urgency. During the call, the victim is asked to share their screen, at which point the group requests remote control through the meeting platform; if granted, this access is used to install an infostealer or remote access trojan. Security researchers have noted the group's methodology mirrors techniques used in a separate large cryptocurrency exchange hack, reflecting a broader shift toward operational, human-centric attacks in the industry.

Associated with: Famous Chollima
First seen: 2025-03 • Last seen: 2025-04

Microsoft tracks this actor as Emerald Sleet, the name it adopted in 2023 for the North Korean state group formerly designated THALLIUM, which other researchers describe as overlapping with Kimsuky and Velvet Chollima. The group has remained highly active, primarily conducting espionage against individuals working in international affairs, especially those whose expertise touches Northeast Asia, as well as non-governmental organizations, government agencies, and media worldwide. Its core tradecraft is spear-phishing, including impersonating reputable academic institutions and non-governmental organizations to elicit expert commentary on North Korea-related foreign policy. In early 2025 Microsoft observed a new approach in which the actor poses as a South Korean government official, builds rapport over time, then sends a spear-phishing email with a PDF attachment directing the recipient to run administrator-level PowerShell code; the code installs a browser-based remote-desktop tool and registers the victim's device using a downloaded certificate, giving the actor remote access for data theft. Microsoft has also documented the group using large language models to research North Korea experts, generate phishing content, and study known software vulnerabilities to identify exploitation paths.

Associated with: Thallium
First seen: 2023-04 • Last seen: 2026-03

FAMOUS CHOLLIMA is a North Korea-nexus threat actor CrowdStrike began naming in August 2024, assessing it as financially motivated and active since at least 2018. CrowdStrike documented operatives fraudulently obtaining remote IT jobs at over 100 mostly US-based technology companies by posing as US residents, then using employee access to install remote-monitoring tools such as RustDesk, AnyDesk and Chrome Remote Desktop and attempt data exfiltration via Git, SharePoint and OneDrive, funneling salaries to North Korea. Other reporting links the group to the Contagious Interview campaign, in which fake recruiters lure software developers, particularly those with cryptocurrency or blockchain experience, into fake coding tests delivering the BeaverTail downloader and the InvisibleFerret backdoor to steal browser credentials and cryptocurrency wallet data. Later reporting describes the group, assessed as a Lazarus subgroup, evolving its tooling to include the GolangGhost and PylangGhost remote access trojans and merged BeaverTail and OtterCookie variants with keylogging and screenshot capture, while CrowdStrike's 2026 reporting states its operations doubled year over year in 2025, increasingly using AI-generated identities to target cryptocurrency exchanges, fintech platforms and consumer banks.

First seen: 2024-08 • Last seen: 2026-09