Sapphire Sleet is a North Korean government-linked cyber threat actor focused primarily on cryptocurrency theft and financially motivated intrusion activity. The actor is tracked as part of Microsoft’s DPRK-associated “Sleet” clusters and has been distinguished from other North Korean groups by its emphasis on targeting individuals and organizations in the cryptocurrency ecosystem rather than only conducting large exchange heists. Reported targeting includes employees, executives, and developers at cryptocurrency websites, as well as venture capital firms and other financial organizations. Sapphire Sleet is known for social-engineering-heavy operations, including fake meeting invitations and fraudulent job-recruitment lures designed to obtain initial access. The actor has also been associated with long-running email-based targeting and repeated use of macOS-focused first-stage infection chains and multiple loader families. Its operations have been characterized as targeting individual traders, personal wallets, and personal accounts on cryptocurrency platforms, aligning with North Korea’s broader use of cyber operations to generate revenue. Sapphire Sleet is part of the broader North Korean cyber apparatus that combines financial theft with state objectives. In reporting that differentiates DPRK clusters, Sapphire Sleet is contrasted with Jade Sleet, which is more closely associated with major exchange thefts. High-confidence aliases beyond Sapphire Sleet are not established in the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DPRK-linked cluster focused on crypto theft via targeting individual traders and personal wallets/accounts; noted for extensive macOS-focused initial access/loader experimentation and long-running email lures.
North Korea-linked financially motivated operations targeting crypto and adjacent finance/VC via extensive social engineering infrastructure (fake meeting invites/domains and fake recruiting/job sites).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.