created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
APT38
APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G0082 |
| Aliases | NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM |
| Attribution | North Korea |
| Class | state |
| Active since | 2014 (per ATT&CK description) |
| ATT&CK entry created | 2019-01-29 |
| Techniques mapped | 62 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1005 |
Data from Local System |
T1027.002 |
Software Packing |
T1033 |
System Owner/User Discovery |
T1036.003 |
Rename Legitimate Utilities |
T1036.006 |
Space after Filename |
T1049 |
System Network Connections Discovery |
T1053.003 |
Cron |
T1053.005 |
Scheduled Task |
T1055 |
Process Injection |
T1056.001 |
Keylogging |
T1057 |
Process Discovery |
T1059.001 |
PowerShell |
(First 12 of 62 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Lazarus Group — North Korea-linked actor, same attribution class
- Kimsuky — North Korea-linked actor, same attribution class
- Contagious Interview — North Korea-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G0082 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.