Actors

249 actors

G0032 is the MITRE ATT&CK group identifier for Lazarus Group, also represented under names including Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, and Diamond Sleet. ATT&CK records activity such as acquiring campaign domains and servers, hosting malicious downloads on GitHub, using cloud file-hosting services, harvesting credentials, and communicating over HTTP and HTTPS.

Associated with: Lazarus
First seen: 2017-05 • Last seen: 2017-05

G0067 is the MITRE ATT&CK designation for a North Korean state-sponsored cyber espionage group MITRE assesses has been active since at least 2012, primarily targeting South Korea but also victims in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. MITRE links the group to a series of campaigns conducted between 2016 and 2018, including ones referred to as Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy, FreeMilk, North Korean Human Rights, and Evil New Year 2018. MITRE notes that North Korean group definitions in general show significant overlap, and that some researchers instead report all North Korean state-sponsored cyber activity under a single grouping rather than tracking discrete clusters or subgroups.

Associated with: APT37
First seen: 2018-04 • Last seen: 2018-04

G0082 identifies a financially focused threat group whose documented operations target banks, venture-capital organizations, and other financial entities. Its tradecraft includes spearphishing with malicious attachments, watering-hole activity, counterfeit domains that imitate banks or investment firms, and the deployment of backdoors and web shells for persistent access. After compromise, the group collects host and user information, captures keystrokes and clipboard data, discovers network shares, and transfers files through custom tooling. In financial intrusions, it has manipulated databases and SWIFT-related records, altered printed or displayed transaction data, and used destructive tools to erase evidence or render systems inoperable. The group also employs packed implants, PowerShell, scheduled tasks, service creation, process injection, tunneling utilities, and secure deletion to execute commands, maintain access, move through networks, and frustrate investigation.

Associated with: APT38
First seen: 2019-01 • Last seen: 2019-01

G0094 is the MITRE ATT&CK group identifier for Kimsuky and related tracking names including Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, and PatheticSlug. ATT&CK records spoofed domains, purchased hosting, payload hosting on web services, HTTP and FTP command channels, and archiving and encrypting collected data before exfiltration.

Associated with: Kimsuky
First seen: 2019-08 • Last seen: 2019-08

MITRE ATT&CK documents G0138 as Andariel, a North Korean state-sponsored threat group active since at least 2009 and considered a subset of Lazarus Group, attributed to North Korea's Reconnaissance General Bureau. The group has primarily targeted South Korean government agencies, military organizations, and a variety of domestic companies, including destructive attacks, and has also conducted cyber-financial operations against ATMs, banks, and cryptocurrency exchanges; notable named activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle. Documented techniques include watering-hole attacks (often using zero-day exploits) limited to specific victim IP ranges, exploitation of ActiveX vulnerabilities, spearphishing with malicious Word or Excel attachments and macro lures, hiding executables inside PNG files via steganography, bulk collection of files from compromised systems, and use of publicly available remote access trojans including gh0st RAT and Rifdoor.

Associated with: Andariel
First seen: 2021-09 • Last seen: 2021-09

MITRE ATT&CK profiles Moonstone Sleet (G1036) as a North Korea-linked threat actor conducting both financially motivated attacks and espionage operations that previously overlapped significantly with the Lazarus Group before differentiating its tradecraft from 2023 onward. The group is noted for creating fake companies and personas, including social media and email accounts, to engage victim organizations and gather information ahead of intrusions, and for developing unique malware such as a payload delivered through a fully functioning game. Moonstone Sleet has distributed a trojanized version of the PuTTY utility as a software supply chain compromise, developed malicious npm packages, and delivered payloads through spearphishing attachments and social media services. Observed intermediate loaders such as YouieLoader and SplitLoader create malicious services and perform system, network, and browser information discovery, while the group has also dumped credentials from LSASS memory, used scheduled tasks for persistence and execution, and deployed ransomware for impact, reflecting a mixed espionage and financially motivated operational profile.

Associated with: Moonstone Sleet
First seen: 2024-08 • Last seen: 2024-08

AppleJeus is the MITRE ATT&CK designation for a North Korean state-sponsored group attributed to the Reconnaissance General Bureau, associated with the broader Lazarus Group umbrella and assessed to be closely resourced alongside another Democratic People's Republic of Korea-affiliated group tracked as Temp.Hermit. Active since at least 2018, its mission is generating and laundering revenue for the North Korean government, with the cryptocurrency industry as its primary target. The group is most notably responsible for the 2023 3CX supply chain attack, in which it first compromised an end-of-life trading application downloaded and run inside 3CX's network, then modified the Windows and macOS build environments used to distribute 3CX's own software, delivering trojanized installers signed with a code-signing certificate. During that intrusion it used a browser-information-stealing tool, a macOS backdoor launched via a Launch Daemon, a communications module supporting encrypted channels and process injection into browsers, and DLL search-order hijacking for persistence, while exploiting a Chrome vulnerability for drive-by compromise. More broadly, AppleJeus pairs malicious cryptocurrency software with phishing and selectively deploys backdoors against high-value financial targets.

Associated with: Apple Jeus
First seen: 2025-08 • Last seen: 2025-08

G1052, tracked by MITRE ATT&CK under the name Contagious Interview, is a North Korea-aligned threat group assessed to have been active since 2023, also associated in reporting with the names DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, and TAG-121. The group conducts both cyberespionage and financially motivated operations, including theft of cryptocurrency and credentials, targeting Windows, Linux, and macOS systems, with particular focus on software developers and individuals in cryptocurrency and blockchain roles. Its signature tactic is impersonating recruiters and hiring personnel via fake job advertisements and social-media outreach and interviews, luring victims to download malicious code disguised as coding tests, software, or drivers, often hosted on public code repositories or distributed via malicious package-manager packages. Malware families include a cross-platform tool built on Qt and a Python-based backdoor, used to steal cryptocurrency wallet credentials, credit card data, and browser and keychain credentials, and to establish persistence, alongside AI-generated content and fake-error-message prompts that trick victims into running malicious code.

Associated with: Contagious Interview
First seen: 2025-10 • Last seen: 2025-10

Palo Alto Networks Unit 42 tracks Gleaming Pisces, also publicly known as Citrine Sleet, as a financially motivated North Korean threat actor active since at least 2018 that is closely linked to North Korea's Reconnaissance General Bureau. The group is best known for the AppleJeus operation, in which it distributed fake cryptocurrency trading applications to compromise cryptocurrency-industry organizations and individuals across Windows, macOS, and Linux systems, relying on a family of backdoors including POOLRAT and BADCALL. In a campaign identified in September 2024, Unit 42 assessed with medium confidence that Gleaming Pisces uploaded several poisoned Python packages to the public PyPI software repository, which delivered a newly identified Linux and macOS backdoor the researchers named PondRAT, assessed to be a lighter variant of POOLRAT based on shared code structure, function names, and an identical encryption key. The group's assessed objective in this supply-chain campaign was to compromise software developers' endpoints as a path to gaining access to the developers' employers or downstream customers.

Associated with: Citrine Sleet
First seen: 2024-09 • Last seen: 2026-05

CrowdStrike Intelligence introduced the designation Golden Chollima in a January 2026 reassessment describing how Labyrinth Chollima, a prolific North Korea-nexus adversary previously linked to destructive attacks against South Korean and United States entities and the WannaCry ransomware incident, segmented after 2018 into three specialized adversaries sharing a malware lineage traced through the KorDLL and Hawup code frameworks. Golden Chollima targets economically developed regions with significant cryptocurrency and financial-technology activity, conducting smaller but consistent thefts that CrowdStrike assesses provide steady baseline revenue for the North Korean government. Its toolset originates with malware first seen in 2018 posing as cryptocurrency trading software from a fabricated company, later expanding to additional tools sharing code with one another. Recent operations delivered malicious software packages through fake recruitment offers to reach fintech employees, then pivoted into victim cloud environments to manipulate identity and access controls and divert cryptocurrency to attacker-controlled wallets, while also exploiting browser zero-day vulnerabilities. CrowdStrike reports that Golden Chollima and related adversaries continue sharing tooling and infrastructure, reflecting coordinated North Korean resourcing, amid a broader 2025 surge in digital-asset theft.

Associated with: Citrine Sleet
First seen: 2026-01 • Last seen: 2026-05