Actors

249 actors

LilacSquid is an espionage-motivated threat actor named and publicly disclosed by Cisco Talos in May 2024 after Talos traced its activity to at least 2021. Talos also tracks the cluster as UAT-4820 and assessed that it sought long-term access for data theft. Confirmed victims included technology organizations serving research and industrial customers in the United States, a European energy organization, and an Asian pharmaceutical organization, suggesting broad collection interests rather than one industry focus. LilacSquid gains entry by exploiting internet-facing applications or using compromised remote-desktop credentials. It then deploys the legitimate MeshAgent remote-management utility, Secure Socket Funneling for tunneling, and custom malware including InkBox, InkLoader, and PurpleInk. PurpleInk, a heavily modified QuasarRAT, supports system discovery, file management and exfiltration, command execution, remote shells, and proxy connections. Talos noted tactical overlap with North Korean groups but did not present that overlap as definitive attribution.

First seen: 2024-05 • Last seen: 2024-10

Google's Threat Intelligence Group reported in November 2025 on UNC1069, also tracked as MASAN, a North Korean state-sponsored threat actor that misuses Google's Gemini AI tools to support cryptocurrency theft operations intended to generate revenue for the regime. The group used Gemini to research cryptocurrency concepts and to help locate victims' cryptocurrency wallet application data, and attempted to use it to develop code for stealing cryptocurrency as well as to craft fraudulent instructions impersonating a software update in order to extract user credentials; Google disabled the account involved. Google's Threat Intelligence Group also observed the group using deepfake images and video lures impersonating individuals in the cryptocurrency industry as part of social engineering campaigns, prompting targets to download a fake Zoom SDK link that distributes its BIGMACHO backdoor. The group's operations rely on social engineering themes related to computer maintenance and credential harvesting.

Associated with: UNC1069
First seen: 2025-11 • Last seen: 2025-11

MB-0010 is a tracking label associated with APT43 and Kimsuky activity. A documented intrusion used a Korean-language CHM decoy to launch hidden PowerShell, retrieve staged VBScript, profile the host, establish scheduled-task persistence, exfiltrate system inventory, and conditionally retrieve a final payload.

Associated with: Kimsuky
First seen: 2026-06 • Last seen: 2026-06

Midnight Neptune is Google Threat Intelligence Group’s name for a North Korean actor formerly tracked as UNC1069. GTIG attributed the cluster to a March 2026 software supply-chain compromise involving the legitimate axios package. After social engineering compromised a maintainer account, the attacker introduced a malicious dependency that acted as a dropper for the WAVESHAPER.V2 backdoor. The affected versions remained available on npm for less than three hours, but the package’s enormous installation base and downstream dependency relationships created potentially broad exposure. GTIG assisted affected customers across at least fifteen industries and thirteen countries. The operation places Midnight Neptune within a growing pattern of North Korean activity targeting open-source repositories and software-development ecosystems, using trusted package relationships and compromised maintainers to distribute malicious code at scale rather than approaching every victim directly.

Associated with: UNC1069
First seen: 2026-07 • Last seen: 2026-09

Moldy Pisces is the name Palo Alto Networks' Unit 42 uses for a suspected North Korean cyber-espionage group that Unit 42 equates with the actor also known as Reaper. The group's primary targets have historically been South Korean government, military, defense-industrial-base, and media-sector organizations. Beginning in 2017 it expanded targeting beyond South Korea to Japan, Vietnam, Nepal, Kuwait, and other parts of the Middle East, with its range of targeted industries broadening alongside this geographic expansion. Moldy Pisces primarily relies on spear-phishing for malware delivery, but Unit 42 also documents the group compromising strategic websites and using torrent file-sharing platforms to distribute malware to victims.

Associated with: TEMP.Reaper
First seen: 2021-09 • Last seen: 2021-09

Microsoft identified Moonstone Sleet in May 2024 as a new, distinct North Korean state-aligned threat actor, previously tracked under the temporary designation Storm-1789; while it initially overlapped heavily with the actor Diamond Sleet, reusing malware such as Comebacker and similar social-engineering delivery methods, it has since moved to its own dedicated infrastructure and tooling. Moonstone Sleet pursues both espionage and revenue-generation objectives against organizations in the software and information technology, education, and defense-industrial-base sectors. Its tradecraft includes distributing trojanized versions of legitimate software such as PuTTY through platforms like LinkedIn and Telegram; creating fake companies, including ones posing as software-development or IT-consulting firms, to solicit collaboration or job applicants; distributing a malicious blockchain-themed game to deliver a custom malware loader; delivering malware disguised as npm-based technical skills assessments; pursuing employment as remote IT workers at legitimate companies; and, beginning in April 2024, deploying custom ransomware against a previously compromised defense-technology company for financial gain, marking the group's first observed use of ransomware.

Associated with: Lazarus
First seen: 2024-05 • Last seen: 2026-09

NNPTGroup corresponds to a self-given persona, "원전반대그룹" (Nuclear [Power Plant] Opposition Group), used by the actor behind the December 2014 breach of Korea Hydro and Nuclear Power (KHNP), in an analysis published in April 2015. The intrusion began with a phishing wave of roughly 5,980 emails sent from 211 compromised accounts, including 55 belonging to former employees, to 3,571 KHNP staff, delivering around 300 pieces of Hangul-word-processor-themed malware, including anti-VM shellcode, MBR- and file-destructive components, and network-attack functionality. Starting December 15, 2014, the persona released stolen KHNP data in five staged waves over about a week through social media and staged online disclosures, seeking public attention around an anti-nuclear narrative. The analysis's technical comparison of phishing-email patterns, command-and-control infrastructure, TeamViewer usage, shellcode, and Hangul-language artifacts linked the intrusion and its malware to the Kimsuky operation, which since 2011 had run cyber-espionage campaigns against South Korean defense, diplomatic, unification, and security-related government bodies, research institutes, and North Korean defectors.

Associated with: Kimsuky
First seen: 2015-04 • Last seen: 2015-04

NEPTUNE is the second-word category Google Threat Intelligence Group uses for North Korean threat actors in its two-word naming system. The first word uniquely identifies the activity cluster, while NEPTUNE communicates its North Korean attribution; the suffix is therefore a taxonomy component rather than a standalone actor.

First seen: 2026-07 • Last seen: 2026-07

McAfee's 2013 report Dissecting Operation Troy identified NewRomanic Cyber Army Team as one of two personas, alongside the Whois (Hacking) Team, that publicly claimed responsibility for the March 20, 2013 Dark Seoul attacks, which wiped the master boot records of tens of thousands of computers at South Korean banks and broadcasters and disrupted ATM access. A pop-up message left on a defaced news site and signed by NewRomanic Cyber Army Team, referencing military-unit terms embedded in the wiper malware itself, claimed theft of tens of millions of customer records. McAfee assessed that the two claiming groups were most likely fabricated personas covering for a single actor behind a covert, South Korea-focused military-espionage campaign it tracked as Operation Troy, which had used spear-phishing-delivered backdoors and an encrypted command-and-control channel to search for files referencing US-Korean military cooperation since at least 2009. Later reporting by HP and Krebs on Security linked the same wiper code and Roman-themed strings to the 2014 Sony Pictures Entertainment attack, and to threat actors alternatively tracked by other researchers as Hastati or Silent Chollima.

Associated with: Guardiansof Peace
First seen: 2013-07 • Last seen: 2014-12

NICKEL ACADEMY is Secureworks' internal designation for cyber operations conducted by North Korea's Reconnaissance General Bureau that are not attributed to a specific subgroup. Secureworks first disclosed the name publicly in December 2017, describing a spearphishing campaign that used a fake CFO job posting to target executives at a European cryptocurrency company, attributing the activity to the actor publicly known as Lazarus Group and noting North Korean interest in bitcoin dating to at least 2013. In a later profile, Secureworks assessed NICKEL ACADEMY has been active since at least 2009, gaining notoriety for the November 2014 attack on Sony Pictures, and primarily targeting South Korean government and commercial organizations while also striking targets globally, including think tanks, financial institutions, transportation and utility companies, NGOs, cryptocurrency exchanges, and defense contractors. Secureworks describes its objectives as disruption, espionage, and financial gain, achieved through spearphishing, malware disguised as legitimate signed applications, and periodic destructive or denial-of-service operations, with tooling that is continually revised across malware families.

Associated with: Lazarus
First seen: 2017-12 • Last seen: 2024-10

Nickel Alley is a North Korean government-aligned threat group tracked by the Sophos Counter Threat Unit as an operator of the Contagious Interview campaign. Sophos publicly profiled the group in March 2026, describing attacks that lure technology professionals with fabricated companies, job advertisements, interviews, skills assessments, and code repositories. Since at least 2024, the actor has persuaded developers to execute malicious projects that install BeaverTail or OtterCookie, while campaigns from mid-2025 used ClickFix instructions to deploy GoLangGhost and PyLangGhost. These tools steal browser credentials, cookies, cryptocurrency-wallet data, files, and system information and provide remote command execution. Nickel Alley also compromises or typosquats package repositories and abuses developer tooling and cloud hosting. Its primary objective is cryptocurrency theft, although Sophos observed indications that access could support supply-chain compromise or corporate espionage against finance and technology organizations.

Associated with: Purple Bravo
First seen: 2026-03 • Last seen: 2026-03

Secureworks Counter Threat Unit researchers track NICKEL FOXCROFT as a targeted threat group they assess with moderate confidence conducts cyberespionage on behalf of the North Korean government. Its targeting is concentrated almost exclusively on South Korea, focusing on individuals and organizations involved in reporting on North Korea, researching Korean-peninsula geopolitics, or supporting North Korean defectors. Consistent with other North Korean-linked groups, NICKEL FOXCROFT relies heavily on social engineering and spearphishing to gain initial access; in at least one instance the group socially engineered victims into surrendering social media credentials, then used that access to more effectively target the victims' associates. Historically the group exploited vulnerabilities in Hangul Word Processor files, a format widely used by South Korean public and private organizations, before shifting to malicious Microsoft Word documents delivered via spearphishing email. These documents deploy tooling that provides credential theft, data exfiltration, screenshot capture, system information collection, and file and directory management capabilities.

Associated with: Scarcruft
First seen: 2023-05 • Last seen: 2024-10

Tracked by SecureWorks Counter Threat Unit researchers as a subgroup of a larger North Korean cluster the unit calls Nickel Academy, Nickel Gladstone is assessed with high confidence to focus on acquisitive financial crime against financial institutions and online criminal activity for financial gain. This focus broadens its geographic scope beyond other North Korean groups to organizations across the Americas, Europe, Africa, and Asia, with particular interest in countries with weaker financial regulatory regimes. Nickel Gladstone rose to prominence in February 2016 with Bangladesh Central Bank's loss of eighty-one million dollars through fraudulent SWIFT messages, and it subsequently conducted similar operations against banks in Vietnam, Ecuador, Taiwan, Chile, and India, and was likely responsible for compromising the Polish Financial Supervision Authority website in 2017. Since at least 2018 it has increasingly targeted cryptocurrency exchanges and decentralized finance organizations using applications that mimic legitimate trading platforms to steal wallet contents, including a later campaign aimed at blockchain-research employees. Its custom malware shows strong ties to earlier North Korean operations, including Operation Blockbuster and the Sony Pictures intrusion.

Associated with: Bluenoroff
First seen: 2021-06 • Last seen: 2021-06

Nickel Hyatt is the Sophos Counter Threat Unit designation for a North Korean government-aligned subgroup of Nickel Academy that has operated since at least 2009. Sophos associates it with names including Andariel, APT45, Onyx Sleet, Silent Chollima, Stonefly, and Jumpy Pisces, while treating Nickel Hyatt as its own tracking construct. The group has pursued espionage, destructive disruption, and financial gain against financial institutions, defense contractors, government agencies, academic think tanks, cybersecurity vendors, refugee-support organizations, nuclear and life-sciences organizations, and other strategic targets. Its geographic focus expanded from South Korea to countries including Japan, the United States, and India. Nickel Hyatt uses public remote-access tools and custom malware such as Rifle, Valefor, UnitBot, and DTrack. Documented operations include destructive attacks, theft of sensitive research, and collection against organizations holding strategically valuable scientific or defense information.

Associated with: Andariel
First seen: 2023-05 • Last seen: 2024-10