APT38 is a North Korea-linked, financially motivated threat actor widely associated with the Lazarus Group ecosystem and commonly tracked under aliases including BlueNoroff, Sapphire Sleet, Stardust Chollima, CageyChameleon, Alluring Pisces, TA444, and UNC1069. The cluster is known for cyber-enabled revenue generation, especially cryptocurrency theft and software supply-chain operations targeting developers, blockchain organizations, and other entities that can provide downstream access to financial assets or cloud environments. Recent activity attributed to this actor includes compromises of trusted npm package maintainers followed by malicious updates to widely used open-source packages, including typo-crypto, debug, chalk, and axios. These operations relied on social engineering against maintainers, trojanized package updates, post-install execution, staged payload delivery, code reuse, obfuscation, anti-analysis checks, and runtime retrieval of additional malicious components. The actor has also been linked to broader software supply-chain compromises affecting AI framework packages, underscoring a focus on trusted developer ecosystems as an initial-access vector at scale. APT38/BlueNoroff has also conducted wallet- and Web3-focused intrusion campaigns using fake meeting and collaboration lures, including Zoom- and Teams-themed social engineering. In these operations, the actor used compromised trusted accounts, victim fingerprinting, credential and wallet targeting, remote payload delivery across Windows and macOS, and Telegram-linked exfiltration workflows. Reported tradecraft includes PowerShell and VBScript loaders, process injection, persistence mechanisms, defense evasion through obfuscation and security-control tampering, and follow-on payload deployment for post-exploitation. The actor’s targeting consistently aligns with financial objectives: cryptocurrency organizations, blockchain developers, cloud-linked developer environments, and software supply chains that can yield broad downstream compromise. Available reporting also places the group among the most active North Korea-linked software supply-chain attackers. While vendor naming varies, the supplied aliases and overlap reporting strongly indicate a single DPRK-linked intrusion cluster operating as a financially driven sub-group within the broader Lazarus constellation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
68 malware families attributed to this actor across reporting.
63 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
Google released an update and thanked us for discovering this attack... CVE-2024-4947... The exploit contains code for two vulnerabilities: the first is used to gain the ability to read and write Chrome process memory from the JavaScript... CVE-2024-4947 ... is the vulnerability in this new compiler.
CERT-EU disclosed on April 2-3, 2026 that the European Commission's Europa web hosting platform on AWS was breached through the Trivy supply chain compromise (CVE-2026-33634). ... Entry vector: Supply chain via compromised Trivy (CVE-2026-33634) ... The CISA KEV remediation deadline for CVE-2026-33634 is now 5 days away (April 8, 2026).
677 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a wallet-targeting threat actor associated with ClickFix-style activity, used here as comparative context for credential and session cleanup after remote-access exposure.
Active software supply chain attacker targeting developer ecosystems such as package registries, CI/CD pipelines, container registries, and IDE extensions to gain access to production systems, cloud environments, and customer networks.
Referenced only as background/comparison for fake meeting lure campaigns; not described as participating in the SMOKE#SCREEN campaign.
Supply chain attacks compromising more than 130 AI framework packages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.