APT38 is a North Korea-linked threat actor widely associated with financially motivated operations, especially large-scale theft targeting banks, cryptocurrency organizations, and other financial assets. The group is commonly treated as a Lazarus/BlueNoroff-related cluster and is also tracked under aliases including Sapphire Sleet, BlueNoroff, TA444, DangerousPassword, Leery Turtle, Masan, Nickel Gladstone, and Nickel Tapestry. Reporting has linked the actor to major theft operations including the 2016 Bangladesh Bank heist and later cryptocurrency-focused intrusions. APT38 combines social engineering, supply-chain compromise, malware deployment, and post-compromise reconnaissance with a strong emphasis on theft and operational stealth. Observed initial access tradecraft includes spearphishing with malicious attachments that attempt to induce victims to enable macros, as well as developer- and cryptocurrency-themed lures. The actor has also been tied to compromise of software ecosystems, including an npm supply-chain intrusion in which malicious dependency code was inserted into numerous packages. On compromised systems, APT38 has demonstrated host and user reconnaissance, including collection of operating system and patch details, identification of logged-in and historical users, enumeration of files and directories, and discovery of installed security software and defensive tooling. The group has used malware capable of clipboard collection, HTTP/HTTPS command-and-control, registry modification, Windows service creation for persistence, and process injection. Associated tooling and campaigns include KEYLIME for clipboard theft, QUICKRIDE for web-protocol command-and-control, CLEANTOAD for registry modification, and broader BlueNoroff-linked cryptocurrency intrusion activity. More recent reporting also connects this actor set to cryptocurrency-targeting campaigns using macOS malware, credential and wallet theft, keylogging, screen and clipboard monitoring, persistence mechanisms, and process injection. APT38’s targeting has centered on financial institutions and cryptocurrency entities, but activity also extends to developers and software supply chains when those pathways support downstream theft objectives. The actor is assessed as operating on behalf of North Korea and is notable for blending espionage-grade intrusion tradecraft with direct revenue-generation operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.