CryptoCore, also known as Crypto-gang, Dangerous Password, and Leery Turtle, is a financially motivated threat actor active since at least 2018 that primarily targets cryptocurrency exchanges and organizations supporting them. Its objective is theft of cryptocurrency through compromise of exchange wallets and employee-held wallet credentials. Operations have principally affected organizations in the United States and Japan. CryptoCore conducts extensive reconnaissance on target organizations, executives, and IT personnel, then uses executive impersonation and spear-phishing to compromise personal or corporate email accounts. It has used cloud-service-themed lures, shortened links, disguised shortcut-file downloaders, and script-based payloads, including the CageyChameleon backdoor. The actor has also targeted password-manager accounts, which may contain wallet keys and credentials useful for further access. It maintains access until wallet multi-factor authentication is removed, then rapidly transfers funds. Reported techniques also include supply-chain compromise, credential dumping, host and process discovery, startup-based persistence, and anti-security-product checks. Attribution to a particular country is not conclusive; reporting has assessed possible Eastern European links only with medium confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
268 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sous-cluster issu d’APT38, spécialisé dans le ciblage exclusif du secteur des cryptomonnaies.
A North Korean financial-operations cluster, likely formed from a split of APT38, targeting cryptocurrency, Web3, and blockchain organizations.
Discussed as part of DPRK cyber capabilities.
A DPRK-nexus financially motivated cluster, assessed as a successor component of APT38, focused on generating revenue for the regime through cryptocurrency-focused operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.