Initial Access
2 techniques·derived
Investment and partnership lures to cryptocurrency and financial staff.
The bank-robbery specialists. Attempted $1.1 billion in theft from financial institutions, and destroys the evidence on the way out.
ATTRIBUTED TONorth Korea › RGB — Reconnaissance General Bureau › Bluenoroff / financial operations element
APT38 — also tracked as BlueNoroff — is the element of North Korea's cyber programme built specifically to steal from financial institutions, and it operates more like a professional heist crew than an espionage group.
Mandiant's 2018 analysis documented attempted theft exceeding $1.1 billion across banks in at least sixteen countries. The methodology is patient and process-driven: obtain access, then spend months — sometimes more than a year — studying the target's internal transaction workflows, approval chains, and reconciliation procedures before attempting anything. The theft itself is fast; the reconnaissance preceding it is not.
The 2016 Bangladesh Bank operation illustrates the model. Operators compromised the bank's environment, studied its SWIFT procedures, deployed malware that manipulated the SWIFT client software and suppressed the printed confirmations staff would have used to notice the fraud, and timed the operation to a weekend spanning different national holidays in Bangladesh, the U.S., and the Philippines to maximise the window before anyone reconciled.
What distinguishes APT38 from criminal financial actors is its willingness to destroy. Operations routinely conclude with wiper deployment across the victim's environment — both to impede forensic reconstruction and to delay recovery while the funds move through laundering channels. Its targets extend beyond banks to cryptocurrency exchanges, ATM networks, and interbank messaging infrastructure.
Down to the named unit where public evidence supports it.
Sanctioned by the U.S. Treasury in September 2019 as Bluenoroff, an RGB-controlled entity, alongside Lazarus and Andariel. The February 2021 DOJ superseding indictment against three RGB officers covers financially motivated operations including bank heists and cryptocurrency theft. Mandiant tracks APT38 as a distinct financially motivated group operating under the same state structure as Lazarus.
Attributing sources
9 designators across 9 organisations.
1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
AIX and Linux implant injected into bank switch application servers, intercepting ISO 8583 transaction messages and approving fraudulent ATM withdrawals.
Malpedia ↗SWIFT manipulation framework that alters transaction records and suppresses printed confirmations to delay detection.
Cross-platform post-exploitation framework with Windows, Linux, and macOS components.
Malpedia ↗Fake venture capital and investment firm personas approaching cryptocurrency startups with funding offers.
Deployed at the conclusion of operations to destroy forensic evidence and delay recovery.
macOS backdoor delivered via a malicious PDF viewer, targeting cryptocurrency firms.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT38 | ||
|---|---|---|---|---|
| CVE-2023-42793KEVransomware | 9.8 | JetBrains TeamCityJetBrains | 1 Oct 2023 | TeamCity RCE exploited for access to build systems at software and financial technology organisations.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2021-44228KEVransomware | 10.0 | Apache Log4j2Apache | 1 Jan 2022 | Log4Shell exploited against internet-facing applications at financial-sector targets for initial access.SRCCISA / FBI / Treasury ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
2 techniques·derived
Investment and partnership lures to cryptocurrency and financial staff.
1 technique·derived
Extended dwell — often more than a year studying transaction workflows before acting.
2 techniques·derived
Injection into bank switch application processes.
2 techniques·derived
Internal transaction procedure documentation.
3 techniques·derived
Alteration of SWIFT transaction records. $1.1bn in attempted theft across at least 16 countries. Wiper deployment after theft to impede forensics.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Investment and partnership lures to cryptocurrency and financial staff
Extended dwell — often more than a year studying transaction workflows before acting
Injection into bank switch application processes
Internal transaction procedure documentation
Alteration of SWIFT transaction records
$1.1bn in attempted theft across at least 16 countries
Wiper deployment after theft to impede forensics
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Curated links to the reports that established what is known about this group.