Nickel Hyatt

2023-05-28 • Secure WorksNICKEL HYATT

Nickel Hyatt is the Sophos Counter Threat Unit designation for a North Korean government-aligned subgroup of Nickel Academy that has operated since at least 2009. Sophos associates it with names including Andariel, APT45, Onyx Sleet, Silent Chollima, Stonefly, and Jumpy Pisces, while treating Nickel Hyatt as its own tracking construct. The group has pursued espionage, destructive disruption, and financial gain against financial institutions, defense contractors, government agencies, academic think tanks, cybersecurity vendors, refugee-support organizations, nuclear and life-sciences organizations, and other strategic targets. Its geographic focus expanded from South Korea to countries including Japan, the United States, and India. Nickel Hyatt uses public remote-access tools and custom malware such as Rifle, Valefor, UnitBot, and DTrack. Documented operations include destructive attacks, theft of sensitive research, and collection against organizations holding strategically valuable scientific or defense information.

Related Actors

First seen: Jul 2017
Last seen: Jun 2026

Related Reports in This Cluster

Top Authors

View Nickel Hyatt reports only

View Nickel Hyatt reports only