Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false

APT38

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide.

Attribute Detail
ATT&CK ID G0082
Aliases NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM
Attribution North Korea
Class state
Active since 2014 (per ATT&CK description)
ATT&CK entry created 2019-01-29
Techniques mapped 62

Attribution — as claimed

Stated by MITRE ATT&CK (state attribution).

Known TTPs

Technique Name
T1005 Data from Local System
T1027.002 Software Packing
T1033 System Owner/User Discovery
T1036.003 Rename Legitimate Utilities
T1036.006 Space after Filename
T1049 System Network Connections Discovery
T1053.003 Cron
T1053.005 Scheduled Task
T1055 Process Injection
T1056.001 Keylogging
T1057 Process Discovery
T1059.001 PowerShell

(First 12 of 62 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Lazarus Group — North Korea-linked actor, same attribution class
  • Kimsuky — North Korea-linked actor, same attribution class
  • Contagious Interview — North Korea-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G0082 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.