Actors

249 actors

NickelJuniper is tracked by Secureworks Counter Threat Unit researchers, who assess with moderate confidence that the group conducts espionage on behalf of the North Korean government. The group has targeted South Korea and Russia, focusing on government entities and the cryptocurrency industry, and has displayed both financial and intelligence-gathering motivations. NickelJuniper typically gains initial access through phishing, has leveraged a known WinRAR vulnerability, and shows a preference for building intermediary infection stages with scripting languages such as VBScript and Windows Batch. Secureworks' profile also lists other industry names associated with this cluster, including Konni, Opal Sleet, and OSMIUM, and notes tooling and behavioral overlaps between NickelJuniper and two other Secureworks-tracked clusters, NICKEL FOXCROFT and NICKEL KIMBALL, suggesting related or shared North Korean cyber operations.

Associated with: Konni
First seen: 2024-10 • Last seen: 2024-11

NICKEL KIMBALL is a designation used by SecureWorks for a threat group assessed to have operated on behalf of the North Korean government since at least 2012. The group primarily targets non-governmental organizations, think tanks, diplomatic and military organizations, economic groups, and research entities involved with North Korean policy and relations, initially focusing on South Korean organizations before expanding internationally; it also seeks access to online accounts and networks used to track North Korean defectors and their relatives. NICKEL KIMBALL conducts extensive spearphishing operations using typosquatted or thematically relevant domains, combined with increasingly elaborate social engineering built from research into targets' social media presence and other public information. Its tooling is generally distinct from other North Korea-linked groups, historically relying on malicious Hangul Word Processor documents when targeting South Korean entities, and evolving to use more widely adopted Microsoft Word and PDF formats as its targeting expanded internationally; malware associated with the group's activity includes several custom remote access trojans and downloader tools.

Associated with: Kimsuky
First seen: 2022-05 • Last seen: 2024-10

Nickel Tapestry is the Sophos Counter Threat Unit designation for North Korean fraudulent IT-worker activity conducted to generate revenue for the state. Sophos described the cluster in October 2024 after incident-response investigations found workers using stolen or fabricated identities to obtain remote employment at Western companies. The operation relies on cloned resumes, shared personas, facilitators and laptop farms, residential proxies, VPNs, virtual desktops, and remote-access tools to conceal workers’ locations and maintain corporate access. Workers collect salaries, redirect equipment and payments, and sometimes share jobs or references among coordinated personas. The activity has expanded beyond employment fraud: observed workers exfiltrated proprietary data, stole intellectual property, and demanded cryptocurrency ransoms after termination. Nickel Tapestry has also used remote desktop software and virtual-camera tools to evade technical and video-verification controls, creating both an insider threat and a path to additional financial gain through extortion.

Associated with: Famous Chollima
First seen: 2024-10 • Last seen: 2026-08

OFFICE 91 is listed by the U.S. Treasury's Office of Foreign Assets Control as an alternate name for Lazarus Group. The designation places the name within the broader set of labels used for the sanctioned North Korean actor rather than defining a separate group.

Associated with: Lazarus
First seen: 2019-09 • Last seen: 2019-09

Onyx Sleet is Microsoft’s designation for a North Korean threat actor first observed by the company in 2014. Microsoft publicly profiled the group under this name in July 2024, describing a long-running cyber-espionage mission that later expanded to financial gain. The actor primarily targets military, defense, engineering, energy, technology, construction, education, and manufacturing organizations in India, South Korea, the United States, and elsewhere. Earlier campaigns relied on spear-phishing, while newer operations frequently exploit publicly disclosed vulnerabilities in internet-facing products to deploy loaders, downloaders, custom backdoors, and remote-access trojans. Onyx Sleet maintains an extensive evolving toolset that includes Dtrack, TigerRAT, SmallTiger, LightHand, ValidAlpha, Dora RAT, ransomware, and open-source administration or tunneling utilities. Microsoft also maps the activity to Andariel, Silent Chollima, Stonefly, DarkSeoul, and TDrop2 and notes overlap with other North Korean ransomware infrastructure.

Associated with: Plutonium
First seen: 2022-07 • Last seen: 2024-09

Opal Sleet is Microsoft's current name for North Korean threat activity previously tracked as OSMIUM. Microsoft's cross-vendor taxonomy table also maps the activity to Konni.

Associated with: Osmium
First seen: 2023-04 • Last seen: 2023-10

PAEKTUSAN is Google’s designation for a North Korean government-backed threat actor that has targeted aerospace and defense personnel through fraudulent recruitment. Google described two campaigns against professionals in Brazil and other regions: one used an account impersonating a human-resources director at a Brazilian aerospace company to phish employees at another aerospace firm, while another posed as a recruiter from a major United States aerospace company. The actor contacted prospective victims through email, social media, and likely messaging applications with false job opportunities. Malicious links led to a document containing a job-posting lure that installed AGAMEMNON, a C++ downloader. Google assessed that these campaigns were consistent with Operation Dream Job, a broader North Korean pattern of weaponizing attractive employment offers to compromise people with access to strategically valuable organizations and information.

First seen: 2024-06 • Last seen: 2024-06

Google's Threat Analysis Group identifies Pronto as a North Korean government-backed group that concentrates on targeting diplomats globally, with observed activity against diplomatic targets in Brazil consistent with this broader pattern. In one documented case, Google blocked a Pronto campaign that used a denuclearization-themed phishing lure paired with the group's typical phishing kit, a fake PDF viewer that presents victims with a login prompt before allowing them to view the lure document, thereby harvesting their credentials. In a separate case, Pronto used lures themed around North Korea news coverage to direct diplomatic targets to credential-harvesting pages. This activity forms part of a broader pattern of North Korean government-backed cyber espionage against diplomatic, government, technology, aerospace, and financial targets in Brazil, alongside other North Korean groups observed pursuing cryptocurrency theft and job-themed social engineering in the region.

First seen: 2024-06 • Last seen: 2024-06

PUKCHONG is Google’s designation for a North Korean government-backed threat actor also tracked as UNC4899. Google described the cluster in June 2024 while reporting a campaign against cryptocurrency professionals in Brazil and other regions. The actor approached targets through social media with an apparent job opportunity at a well-known cryptocurrency company, first sending benign job-description and skills-questionnaire documents. Interested candidates were then directed to complete a coding test by downloading a project from GitHub. The project contained a trojanized Python application presented as a cryptocurrency-price tool; when specified conditions were met, it contacted attacker-controlled infrastructure to retrieve a second-stage payload. The operation combined patient recruiter impersonation, staged trust-building, developer-focused technical assessments, and weaponized source-code hosting to compromise people with access to cryptocurrency and financial-technology organizations.

Associated with: UNC4899
First seen: 2024-06 • Last seen: 2025-11

PatheticSlug is a name Cloudflare's Cloudforce One threat intelligence team uses for a North Korea-linked threat actor referenced in Cloudflare's 2026 threat report as an example of a broader industry shift toward abusing trusted cloud platforms to mask malicious activity. Cloudflare describes the group as exploiting the reputation shield of legitimate cloud ecosystems to disguise payload delivery, specifically using Google Drive and Dropbox to host XenoRAT payloads while leveraging GitHub for covert command-and-control communications, blending its traffic into legitimate enterprise activity rather than relying only on conspicuous attacker-owned infrastructure and communications.

Associated with: Kimsuky
First seen: 2026-03 • Last seen: 2026-03