Actors

249 actors

Wiz's Customer Incident Response Team first identified and named JINX-0164 in a report published in late May 2026, describing it as a previously unreported, financially motivated cluster active since at least mid-2025, targeting developers and organizations across the cryptocurrency industry, including exchanges, DeFi protocol teams, and blockchain tooling firms. Operators build credible LinkedIn personas posing as recruiters, investors, or business contacts, then lure victims into virtual meetings on spoofed conferencing sites where a staged technical problem prompts download of a disguised fix, delivering custom macOS malware: a Python-based infostealer and remote-access tool harvesting browser and desktop cryptocurrency wallet data, credentials, SSH keys, cloud tokens, and messaging-app data, plus a lightweight backdoor. In April 2026 the group also trojanized a popular cryptocurrency SDK package on a public package registry to distribute the backdoor, showing a supply-chain capability alongside its social-engineering operations, with stolen developer credentials used to move laterally into internal code repositories and CI/CD pipelines. Researchers found tactical similarities to other North Korea-linked clusters but no confirmed infrastructure overlap; a later report separately described the group as North Korea-linked.

Associated with: Sapphire Sleet
First seen: 2026-05 • Last seen: 2026-05

GitHub disclosed a low-volume social engineering campaign, publicly attributed with high confidence to a group it identified as Jade Sleet per Microsoft Threat Intelligence naming and TraderTraitor per CISA, that targeted personal accounts of technology-industry employees, primarily those connected to blockchain, cryptocurrency, and online gambling organizations, through fraudulent GitHub repository invitations paired with malicious npm package dependencies. Checkmarx subsequently confirmed the activity was tied to Jade Sleet, TraderTraitor, and the broader Lazarus Group, describing what it assessed as the first nation-state use of open-source supply chain infiltration: attackers built rapport with targets through fake developer and recruiter personas on LinkedIn, Slack, and Telegram before inviting them to collaborate on repositories containing paired first- and second-stage npm packages that were progressively refined with additional obfuscation and more robust error handling. Indicators from the campaign overlapped with the contemporaneous compromise of IT management firm JumpCloud, and the group used compromised developer trust and reputation to reach cryptocurrency and blockchain sector victims.

Associated with: Trader Traitor
First seen: 2023-07 • Last seen: 2026-09

Jasper Sleet is Microsoft’s designation for North Korean remote IT-worker activity, previously tracked as Storm-0287. Microsoft publicly profiled the actor under the Jasper Sleet name in June 2025 while describing a broader operation it had tracked since at least early 2020. The workers obtain remote software-development, web-development, and administrative roles using stolen or rented identities, fabricated documents, false professional profiles, staffing intermediaries, and facilitators who manage local devices, bank accounts, phone numbers, and employment checks. Their operations generate revenue for the North Korean government while enabling theft of source code, intellectual property, trade secrets, and other sensitive information; some workers have also extorted employers. Jasper Sleet uses VPNs, proxies, remote-management tools, laptop farms, developer platforms, and increasingly AI-assisted image editing and voice-changing software to conceal workers’ identities and locations and improve fraudulent applications.

Associated with: Famous Chollima
First seen: 2025-06 • Last seen: 2026-08

Palo Alto Networks Unit 42 tracks Jumpy Pisces as a North Korean state-sponsored threat actor operating under the Reconnaissance General Bureau, also publicly known as Andariel, Hidden Cobra, and Onyx Sleet, and assessed to be a subgroup of the broader Lazarus Group that branched out around 2013. The group has historically conducted cyberespionage and financial crime, including development of the custom Maui ransomware for which a member was indicted by the U.S. Department of Justice, primarily targeting South Korean aerospace and defense, financial-services, and utilities and energy organizations through spear phishing, watering-hole attacks, and supply-chain compromise. In an incident identified in 2024, Unit 42 assessed with high confidence that Jumpy Pisces gained initial access to a victim network via a compromised account and used the Sliver framework and its custom DTrack malware for lateral movement, and assessed with moderate confidence that the same access was subsequently leveraged, with some cooperation from Jumpy Pisces, to deploy Play ransomware, marking the group's first observed collaboration with an established ransomware operation.

Associated with: Andariel
First seen: 2024-06 • Last seen: 2025-04

KTA082 is Kroll’s tracking designation for the North Korean APT group more widely known as Kimsuky. In March 2024, Kroll linked the designation to an attempted intrusion that exploited authentication-bypass vulnerabilities in ConnectWise ScreenConnect to deploy a newly observed BABYSHARK variant. After gaining interactive access, the operator used command-line and Microsoft utilities to execute heavily obfuscated Visual Basic stages whose randomized code, junk content, and unique download paths complicated detection. The malware disabled Office macro warnings, collected host, user, network, security-product, process, and software information, encoded the results with a native certificate utility, and exfiltrated them to command-and-control infrastructure. It also established a scheduled task that repeatedly retrieved and executed additional code. Kroll connected this behavior to Kimsuky’s earlier macro-based spear-phishing and information-stealing operations while retaining uncertainty about the final payload delivered during the observed incident.

Associated with: Kimsuky
First seen: 2024-03 • Last seen: 2024-03

Kaspersky researchers first identified this activity in September 2013 as an ongoing cyber-espionage campaign against South Korean think tanks and government-linked bodies, including the Sejong Institute, the Korea Institute for Defense Analyses, the Ministry of Unification, and Hyundai Merchant Marine, delivered through spear-phishing and a modular spying toolset that logged keystrokes, harvested files, and communicated with operators via a free Bulgarian webmail account while deliberately evading a Korean antivirus vendor's software. What was initially described as a single operation was later tracked by multiple researchers and government agencies as a persistent, North Korea-linked group active since at least 2012, tasked with global intelligence collection on foreign policy, nuclear issues, and Korean Peninsula security, primarily through spearphishing and watering-hole attacks delivering malware such as BabyShark. Subsequent analysis found targeting had expanded beyond South Korea, Japan, and the United States to include Russia and Europe, hitting COVID-19 vaccine researchers, the UN Security Council, human rights groups, journalists, and South Korean military and defense institutes, using an evolving modular spyware suite, weaponized Word documents, and reused infrastructure across years of continuous operations.

First seen: 2013-09 • Last seen: 2026-09

Konni is the name Cisco Talos gave in 2017 to a remote-access malware family it found delivering information-stealing and remote-control capability through spear-phishing emails with decoy documents, in campaigns dating back to 2014 that increasingly targeted individuals and organizations connected to North Korea-related diplomatic and humanitarian affairs. The malware and associated intrusion activity were subsequently tracked by other vendors as a distinct campaign and, later, an actor: Palo Alto Networks referred to malware families "typically associated with the Konni Group" in a 2019-2020 spear-phishing campaign against a U.S. government agency, and Cluster25 described a 2022 operation as conducted by the "North Korean APT group Konni" targeting Russia's diplomatic sector. Malwarebytes, by contrast, assessed in 2022 that the North Korean threat actor using Konni malware operates under what it called the Kimsuky umbrella, illustrating ongoing disagreement among researchers over whether Konni represents an independent group or a toolset shared within a broader North Korean cluster.

First seen: 2017-05 • Last seen: 2026-08

Labyrinth Chollima is a DPRK-nexus adversary that CrowdStrike has tracked since at least 2009, assessed as likely affiliated with Bureau 121 of North Korea's Reconnaissance General Bureau and motivated by financial gain, intelligence collection, destruction, and intellectual-property theft. Its lineage traces to the KorDLL malware framework, active 2009-2015, which evolved into the Hawup framework and, between 2018 and 2020, spawned two specialized offshoots that CrowdStrike now tracks as separate adversaries: one pursuing steady, lower-value cryptocurrency and fintech theft rooted in a 2018 fake cryptocurrency-trading-application operation, and another responsible for some of the largest cryptocurrency heists attributed to North Korea. Core Labyrinth Chollima itself narrowed toward espionage using a distinct malware lineage, and by 2022 adopted a kernel-level toolset alongside zero-day exploits in browsers, drivers, and Windows. The group maintains cross-platform Windows, Linux, macOS, and Android implants; has targeted cryptocurrency exchanges, fintech, and technology firms through trojanized applications, fake recruiter personas, and backdoored coding challenges; and has more recently prioritized European and North American manufacturing, defense, and logistics organizations using employment-themed lures and messaging-app-delivered trojanized files.

Associated with: Lazarus
First seen: 2018-02 • Last seen: 2026-06

AhnLab's ASEC identified Larva-24005 as a sub-group of the Kimsuky threat group receiving support from North Korea, with the name newly assigned under AhnLab's threat-actor naming system. The group breaches poorly protected Windows servers in South Korea, in some cases exploiting the BlueKeep remote-code-execution vulnerability, and after gaining access installs the open-source RDPWrap utility to enable remote desktop connections along with a custom keylogger. Using this compromised infrastructure, Larva-24005 sets up XAMPP-based web, database, and mail-sending environments to host phishing pages and send phishing emails disguised as Zoom meeting invitations or web portal login pages impersonating services such as iCloud, OneDrive, Outlook, Naver, and Google. Its primary targets are South Korean and Japanese individuals involved with North Korea issues, including university professors researching the North Korean regime, whom it profiles through browser search history and news reading before crafting tailored spear-phishing lures. Captured keylogger data and read receipts allow the group to confirm targeting success and refine subsequent phishing operations against Korea- and Japan-based victims.

Associated with: Kimsuky
First seen: 2025-02 • Last seen: 2025-04

Larva-25004 is AhnLab’s designation for a Kimsuky-linked activity group discovered while investigating malware signed with certificates stolen from Korean companies. AhnLab named and began tracking the cluster in May 2025, tracing related activity back to at least August 2023. Its targets have included South Korean public enterprises, defense organizations, research institutes, and job seekers. The group delivers executable JSE, PIF, and SCR files disguised as business documents through spear-phishing, and has also compromised an internal Bizbox Alpha messenger update server to distribute a trojanized client during automatic updates. Its toolset includes HttpSpy, Memload, HttpTroy, NikiDoor, information stealers, proxy software, and document-search utilities. Some droppers carry apparently stolen code-signing certificates, while oversized or packed payloads, randomized padding, encryption, scheduled-task persistence, and virtual-environment checks help evade analysis and maintain access.

Associated with: Kimsuky
First seen: 2025-05 • Last seen: 2025-11

Larva-25010 is AhnLab ASEC's tracking designation, used in an October 2025 Korean-language report consolidating a series of ASEC threat notes issued after the August 2025 DEF CON 33 release of "APT Down: The North Korea Files," a Phrack Magazine report by researchers "saber" and "cyb0rg" describing a leaked data dump from a workstation the authors attributed to an operator of the Kimsuky group. Building on that leak, the compiled ASEC posts describe continuing compromise of South Korean administrative, military, and telecommunications organizations, a warning about an apparently shared government-agency password, indications the operator's Korean-language proficiency was weak, raising the possibility of a Chinese national behind the keyboard, reconnaissance against Taiwan and Japan, leakage of an APPM product with attempted decryption of its data, and preparations to phish Naver and Kakao login pages.

Associated with: Kimsuky
First seen: 2025-10 • Last seen: 2025-10

Larva-26005 is a threat actor tracked by AhnLab's ASEC, observed distributing a backdoor called Xctdoor to users in South Korea. ASEC linked the actor's recent activity to a malware family first seen in 2020 that other researchers attributed to the Lazarus group based on a shared HTTP wrapper library, overlapping remote-access-trojan functionality, ransomware deployment, WordPress-based command-and-control infrastructure, and targeting of Korean-speaking victims; ASEC assesses the current activity is likewise linked to North Korea but tracks it separately as Larva-26005. In 2026, the group distributed C++ and Go versions of Xctdoor through installers disguised as legitimate security software and through malicious shortcut files sent in spear-phishing emails using lures on topics such as account statements, leases, contracts, and job applications, targeting both corporate and general users. Earlier activity attributed to the same actor included compromising an internet-facing web server, abusing an exposed groupware upload page to spread malware internally, and tampering with the update mechanism of a Korean enterprise resource planning product to deliver the backdoor, giving the actor remote command execution, file theft, and system-monitoring capability on infected hosts.

Associated with: Lazarus
First seen: 2026-08 • Last seen: 2026-08

LAWRENCIUM is a former Microsoft tracking name for North Korean activity now called Pearl Sleet. Microsoft's taxonomy also shows the developmental identifier DEV-0215 mapped to LAWRENCIUM and Pearl Sleet.

Associated with: DEV-0215
First seen: 2023-04 • Last seen: 2023-04

Novetta coined the name "Lazarus Group" as part of Operation Blockbuster, an industry coalition it led with partners including Kaspersky Lab and Cisco Talos that publicly disclosed its findings on 24 February 2016. Kaspersky's contribution to that release traced the actor's activity back to 2009, noted a spike from 2011 and steady growth from 2013, and folded malware and campaigns previously tracked separately, including Operation Troy, DarkSeoul, Hangman (2014-2015) and Wild Positron/Duuzer (2015), into a single cluster alongside the malware publicly attributed to the Sony Pictures Entertainment (SPE) breach. Novetta's own reverse engineering identified a spreader built specifically with SPE network and account details to deliver a destructive wiper. Across the analyzed malware set the group fielded a large toolkit of remote-administration trojans built on a shared code base, worm-style network spreaders, peer-to-peer staging tools, and web-server backdoors, alongside spearphishing that included a Hangul Word Processor zero-day, password-protected ZIP droppers, self-deleting batch scripts, and sandbox-evasion checks. Targets spanned financial, media and manufacturing organizations with a recurring focus on South Korea, and operations blended cyberespionage with destructive, data-wiping attacks.

First seen: 2016-02 • Last seen: 2026-09