Threat actor
APT38
Last fetched
APT38 is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 119 techniques and also known as 6 other names.
Also known as
NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM
Description
[APT38](https://attack.mitre.org/groups/G0082) is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.(Citation: CISA AA20-239A BeagleBoyz August 2020) Active since at least 2014, [APT38](https://attack.mitre.org/groups/G0082) has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which [APT38](https://attack.mitre.org/groups/G0082) stole $81 million, as well as attacks against Bancomext (Citation: FireEye APT38 Oct 2018) and Banco de Chile (Citation: FireEye APT38 Oct 2018); some of their attacks have been destructive.(Citation: CISA AA20-239A BeagleBoyz August 2020)(Citation: FireEye APT38 Oct 2018)(Citation: DOJ North Korea Indictment Feb 2021)(Citation: Kaspersky Lazarus Under The Hood Blog 2017) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.
Techniques by tactic
Command and Control
- T1001.003 · Protocol or Service Impersonation
- T1008 · Fallback Channels
- T1071.001 · Web Protocols
- T1090.001 · Internal Proxy
- T1090.002 · External Proxy
- T1102.002 · Bidirectional Communication
- T1104 · Multi-Stage Channels
- T1105 · Ingress Tool Transfer
- T1132.001 · Standard Encoding
- T1571 · Non-Standard Port
- T1573.001 · Symmetric Cryptography
Discovery
- T1010 · Application Window Discovery
- T1012 · Query Registry
- T1016 · System Network Configuration Discovery
- T1033 · System Owner/User Discovery
- T1046 · Network Service Discovery
- T1049 · System Network Connections Discovery
- T1057 · Process Discovery
- T1082 · System Information Discovery
- T1083 · File and Directory Discovery
- T1124 · System Time Discovery
- T1135 · Network Share Discovery
- T1217 · Browser Information Discovery
- T1518.001 · Security Software Discovery
- T1680 · Local Storage Discovery
Execution
- T1047 · Windows Management Instrumentation
- T1053.003 · Cron
- T1053.005 · Scheduled Task
- T1059.001 · PowerShell
- T1059.003 · Windows Command Shell
- T1059.005 · Visual Basic
- T1106 · Native API
- T1203 · Exploitation for Client Execution
- T1204.001 · Malicious Link
- T1204.002 · Malicious File
- T1569.002 · Service Execution
- T1574.001 · DLL
- T1574.013 · KernelCallbackTable
Impact
- T1485 · Data Destruction
- T1486 · Data Encrypted for Impact
- T1489 · Service Stop
- T1491.001 · Internal Defacement
- T1529 · System Shutdown/Reboot
- T1561.001 · Disk Content Wipe
- T1561.002 · Disk Structure Wipe
- T1565.001 · Stored Data Manipulation
- T1565.002 · Transmitted Data Manipulation
- T1565.003 · Runtime Data Manipulation
Privilege Escalation
- T1053.003 · Cron
- T1053.005 · Scheduled Task
- T1055 · Process Injection
- T1055.001 · Dynamic-link Library Injection
- T1078 · Valid Accounts
- T1098 · Account Manipulation
- T1134.002 · Create Process with Token
- T1543.003 · Windows Service
- T1547.001 · Registry Run Keys / Startup Folder
- T1547.009 · Shortcut Modification
- T1548.002 · Bypass User Account Control
Stealth
- T1027.002 · Software Packing
- T1027.007 · Dynamic API Resolution
- T1027.009 · Embedded Payloads
- T1027.013 · Encrypted/Encoded File
- T1036.003 · Rename Legitimate Utilities
- T1036.004 · Masquerade Task or Service
- T1036.005 · Match Legitimate Resource Name or Location
- T1036.006 · Space after Filename
- T1055 · Process Injection
- T1055.001 · Dynamic-link Library Injection
- T1070 · Indicator Removal
- T1070.003 · Clear Command History
- T1070.004 · File Deletion
- T1070.006 · Timestomp
- T1078 · Valid Accounts
- T1134.002 · Create Process with Token
- T1140 · Deobfuscate/Decode Files or Information
- T1202 · Indirect Command Execution
- T1218 · System Binary Proxy Execution
- T1218.001 · Compiled HTML File
- T1218.005 · Mshta
- T1218.007 · Msiexec
- T1218.011 · Rundll32
- T1480.002 · Mutual Exclusion
- T1542.003 · Bootkit
- T1564.001 · Hidden Files and Directories
- T1574.001 · DLL
- T1574.013 · KernelCallbackTable
- T1620 · Reflective Code Loading
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to APT38 today — this states the absence of a published link, not that APT38 has no infrastructure.
References
- https://attack.mitre.org/groups/G0082
- https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2021GTR.pdf
- https://www.justice.gov/opa/pr/three-north-korean-military-hackers-indicted-wide-ranging-scheme-commit-cyberattacks-and
- https://us-cert.cisa.gov/ncas/alerts/aa20-239a
- https://services.google.com/fh/files/misc/apt38-un-usual-suspects.pdf
- https://securelist.com/lazarus-under-the-hood/77908/
- https://www.crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the-month-for-april-stardust-chollima/
- https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/microsoft-threat-actor-naming?view=o365-worldwide
- https://www.secureworks.com/research/threat-profiles/nickel-gladstone
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from APT38 into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.