APT38 is a North Korea-linked threat actor widely associated with financially motivated operations, especially large-scale theft targeting banks, financial institutions, cryptocurrency businesses, and related ecosystems. The group is commonly treated as a Lazarus/BlueNoroff-affiliated cluster or subgroup in vendor reporting, and has been referred to by aliases including BlueNoroff, Sapphire Sleet, DangerousPassword, Leery Turtle, Masan, Nickel Tapestry, and TA444 in overlapping or partially overlapping attribution contexts. Public reporting consistently places the actor within the Democratic People’s Republic of Korea’s cyber apparatus. APT38 is best known for high-impact financial operations, including involvement in major bank theft activity such as the Bangladesh Bank heist, and later campaigns focused on cryptocurrency exchanges, Web3 organizations, and crypto-focused businesses. More recent activity has also included software supply-chain compromise, including compromise of npm ecosystem packages used to target developers and downstream users. The actor’s targeting frequently blends direct financial theft with access operations against developers, employees of cryptocurrency organizations, and other personnel who can provide a path to wallets, credentials, cloud resources, or internal code repositories. Tradecraft associated with APT38 includes heavy use of social engineering, spearphishing, and lures themed around jobs, meetings, code reviews, investment, or cryptocurrency research. The group has repeatedly relied on user execution, including malicious attachments and macro-enabled documents, and has also used more elaborate deception such as fake meeting workflows and impersonation of trusted business contacts. In developer- and supply-chain-focused operations, the actor has abused legitimate platforms and ecosystems to distribute malicious dependencies or trojanized packages. Observed post-compromise behavior includes host reconnaissance and victim profiling, such as collecting detailed operating system and patch information, enumerating files and directories, identifying logged-in and historical users, and discovering installed security software and defensive tooling. The group has also demonstrated persistence through creation of Windows services and registry modification. Malware and tooling associated with APT38 reporting include CLEANTOAD for registry modification, KEYLIME for clipboard collection, and QUICKRIDE for HTTP/HTTPS backdoor communications. Reporting also links overlapping BlueNoroff/TA444 activity to multi-stage malware chains on macOS, credential theft, keylogging, screen and clipboard monitoring, process injection, and theft of cryptocurrency wallet data. APT38 commonly uses application-layer protocols such as HTTP and HTTPS for command and control, and has shown an ability to adapt delivery and persistence mechanisms across Windows and macOS environments. Across campaigns, the actor has demonstrated strong operational focus on stealth, persistence, credential access, and monetization, while increasingly exploiting trusted services, cloud resources, developer tooling, and supply-chain relationships to reach high-value financial and cryptocurrency targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
74 malware families attributed to this actor across reporting.
69 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
Google released an update and thanked us for discovering this attack... CVE-2024-4947... The exploit contains code for two vulnerabilities: the first is used to gain the ability to read and write Chrome process memory from the JavaScript... CVE-2024-4947 ... is the vulnerability in this new compiler.
CERT-EU disclosed on April 2-3, 2026 that the European Commission's Europa web hosting platform on AWS was breached through the Trivy supply chain compromise (CVE-2026-33634). ... Entry vector: Supply chain via compromised Trivy (CVE-2026-33634) ... The CISA KEV remediation deadline for CVE-2026-33634 is now 5 days away (April 8, 2026).
559 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromised an npm supply chain by injecting a malicious dependency into over 140 packages, targeting developers and related communities.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Mentioned only as an annotation/tag associated with the ATT&CK technique Process Injection (T1055); no campaign or activity by this group is described in the content.
Mentioned only in an annotation/list associated with the detection content; no actor-specific activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.