Sapphire Sleet is a North Korea-linked threat actor associated with financially motivated cyber operations, including software supply-chain compromises and theft of sensitive data and cryptocurrency assets. The group has been linked to campaigns in which trusted maintainers of widely used open-source JavaScript packages were socially engineered and then used to publish malicious updates to packages in the NPM ecosystem, enabling downstream compromise at scale. Reported objectives include theft of passwords, personal data, and cryptocurrency. Sapphire Sleet is notable for relying heavily on social engineering rather than exploitation of software vulnerabilities to obtain initial access. In the observed supply-chain intrusions, the actor abused legitimate maintainer access to distribute malware through popular packages, creating broad downstream exposure for organizations that automatically consumed updated dependencies. This tradecraft reflects a scalable initial-access and post-compromise model centered on trust abuse, defense evasion through legitimate distribution channels, and data and asset theft. The actor has been linked by multiple vendors to overlapping tracking clusters and aliases including UNC1069, BlueNoroff, Stardust Chollima, CageyChameleon, and Alluring Pisces. The activity is consistent with North Korean cyber-enabled revenue generation operations conducted under sanctions pressure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.