Skip to content
North KoreaState-SponsoredActiveMITRE G0082Malpedia ↗

APT38

The bank-robbery specialists. Attempted $1.1 billion in theft from financial institutions, and destroys the evidence on the way out.

ATTRIBUTED TONorth Korea › RGB — Reconnaissance General Bureau › Bluenoroff / financial operations element

Open MITRE Navigator layer ↗Download profile JSON
Active
2014–present
Motivation
Financial Gain, Sabotage / Destruction
Aliases
9
Exploited CVEs
2
ATT&CK techniques
10
Cited sources
7

Overview

APT38 — also tracked as BlueNoroff — is the element of North Korea's cyber programme built specifically to steal from financial institutions, and it operates more like a professional heist crew than an espionage group.

Mandiant's 2018 analysis documented attempted theft exceeding $1.1 billion across banks in at least sixteen countries. The methodology is patient and process-driven: obtain access, then spend months — sometimes more than a year — studying the target's internal transaction workflows, approval chains, and reconciliation procedures before attempting anything. The theft itself is fast; the reconnaissance preceding it is not.

The 2016 Bangladesh Bank operation illustrates the model. Operators compromised the bank's environment, studied its SWIFT procedures, deployed malware that manipulated the SWIFT client software and suppressed the printed confirmations staff would have used to notice the fraud, and timed the operation to a weekend spanning different national holidays in Bangladesh, the U.S., and the Philippines to maximise the window before anyone reconciled.

What distinguishes APT38 from criminal financial actors is its willingness to destroy. Operations routinely conclude with wiper deployment across the victim's environment — both to impede forensic reconstruction and to delay recovery while the funds move through laundering channels. Its targets extend beyond banks to cryptocurrency exchanges, ATM networks, and interbank messaging infrastructure.

Attribution

Down to the named unit where public evidence supports it.

North KoreaRGB — Reconnaissance General BureauBluenoroff / financial operations elementConfirmed

Sanctioned by the U.S. Treasury in September 2019 as Bluenoroff, an RGB-controlled entity, alongside Lazarus and Andariel. The February 2021 DOJ superseding indictment against three RGB officers covers financially motivated operations including bank heists and cryptocurrency theft. Mandiant tracks APT38 as a distinct financially motivated group operating under the same state structure as Lazarus.

Attributing sources

Cross-vendor naming crosswalk

9 designators across 9 organisations.

1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • APT38

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Sapphire SleetFormerly COPERNICIUM

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Stardust Chollima

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT38

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • NICKEL GLADSTONE

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Sparkling PiscespartialOverlapping DPRK financial-operations cluster

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Kaspersky GReAT

index ↗
  • BlueNoroff

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Symantec (Broadcom)

index ↗
  • Bluenoroff

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • BeagleBoyzU.S. government designator used in the FASTCash advisories

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

BangladeshVietnamMexicoChileTaiwanIndiaMaltaUnited StatesSouth KoreaPolandTürkiye

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

FASTCashmalware

AIX and Linux implant injected into bank switch application servers, intercepting ISO 8583 transaction messages and approving fraudulent ATM withdrawals.

Malpedia ↗
DYEPACKmalware

SWIFT manipulation framework that alters transaction records and suppresses printed confirmations to delay detection.

MATA frameworkframework

Cross-platform post-exploitation framework with Windows, Linux, and macOS components.

Malpedia ↗
SnatchCrypto luresutility

Fake venture capital and investment firm personas approaching cryptocurrency startups with funding offers.

Custom wiperswiper

Deployed at the conclusion of operations to destroy forensic evidence and delay recovery.

RustBucketbackdoor

macOS backdoor delivered via a malicious PDF viewer, targeting cryptocurrency firms.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT38
CVE-2023-42793KEVransomware9.81 Oct 2023TeamCity RCE exploited for access to build systems at software and financial technology organisations.SRCMicrosoft Threat Intelligence
CVE-2021-44228KEVransomware10.01 Jan 2022Log4Shell exploited against internet-facing applications at financial-sector targets for initial access.SRCCISA / FBI / Treasury

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

5 stages · 10 techniques
  1. 02

    Persistence

    1 technique·derived

    Extended dwell — often more than a year studying transaction workflows before acting.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
10 techniques across 5 tactics · 7 with actor-specific notes

Initial Access

2

Persistence

1
  • T1078Valid Accounts

    Extended dwell — often more than a year studying transaction workflows before acting

Defense Evasion

2

Collection

2

Impact

3

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.